A public proof-of-concept exploit is available for CVE-2026-62911, a high-risk Microsoft Exchange Server flaw affecting Exchange Server 2016, 2019, and Subscription Edition. An unauthenticated remote attacker could execute malicious code, access mailboxes, and use a compromised server to move further through the network; related Exchange flaws can also enable service disruption, account takeover, privilege escalation, and sensitive-data exposure.
Germany’s BSI/CERT-Bund reported that roughly 85% of German on-premises Exchange servers remained vulnerable despite Microsoft’s August security updates, and has notified operators of exposed systems since August 14. Administrators should deploy KB5121573 for Exchange Subscription Edition; Exchange 2016 and 2019 require paid Extended Security Updates after regular support ended in October 2025. Organizations should also limit Exchange web-service access to trusted IP addresses or a VPN, restrict legacy servers to internal access, and plan their replacement.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
CERT-Bund reported that roughly 85% of on-premises Exchange servers in Germany remained vulnerable. It also knew of only nine German Exchange 2016 or 2019 servers with ESU-issued patches installed.
Germany's BSI/CERT-Bund began notifying German network operators about vulnerable Exchange systems exposed in their networks and urged immediate installation of security updates.
Microsoft issued security updates during its August Patch Tuesday, including remediation for the high-risk Exchange Server vulnerability CVE-2026-62911. Exchange SE administrators can apply KB5121573, while Exchange 2016 and 2019 require ESU coverage.
Orange Tsai of DEVCORE demonstrated the Exchange Server authentication-bypass vulnerability CVE-2026-62911 at Pwn2Own Berlin 2026. The vulnerability affects the HTTP.sys-hosted MRSProxy endpoint and can be chained with a file-path validation weakness for SYSTEM-level code execution.
At the end of October, about 92% of roughly 33,000 on-premises Exchange servers in Germany were running unsupported Exchange versions with internet-reachable Outlook Web Access instances.
Regular Microsoft support for Exchange Server 2016 and Exchange Server 2019 ended, leaving those versions dependent on the paid Extended Security Updates program for security fixes.
The Netherlands' NCSC-NL warned that a working exploit for CVE-2026-62911 was circulating online and urged organizations to install available Exchange updates promptly. Microsoft had not confirmed online exploit circulation in its advisory at the time of the report.
Shadowserver identified 21,899 internet-exposed IP addresses fingerprinted as unpatched Microsoft Exchange servers vulnerable to CVE-2026-62911. The largest identified concentrations were approximately 6,200 servers in the United States and 5,100 in Germany.
A public proof-of-concept exploit was released for CVE-2026-62911, which can be used in an exploit chain to compromise vulnerable Exchange servers from the internet without prior authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcehelpnetsecurity.com
Open sourcecsirt.sk
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcecsirt.bj
Open sourceheise.de
Open sourcencsc.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.