Microsoft shipped the fix for CVE-2026-62911 on August 11, 2026. Shadowserver’s daily scans still find nearly 22,000 Microsoft Exchange servers on the public internet that never applied it. The United States leads with about 6,200 unpatched hosts; Germany follows with roughly 5,100. Microsoft describes the flaw as authentication bypass by capture-replay, which lets an authorized attacker elevate privileges over the network. If your cybersecurity backlog still ranks Exchange behind the week’s model launches, that scan is the ticket you write tonight.
Shadowserver: 22,000 Exchange Hosts Still Unpatched After August 11
The 22,000 figure is a scan count. Shadowserver probes the internet every day, and Help Net Security’s report of those results belongs in a change record, because it shows the August 11 update is still missing from CAS and mailbox roles that answer on 443.
Three weeks is a long window for a critical Exchange authentication bypass. You don’t need a custom implant to abuse capture-replay. You need a captured authentication exchange and a server that still accepts the replay. That is a low bar for anyone who already has a packet capture, a proxy position, or a remote desktop into a user’s session.

Look at the geography. About 6,200 of those hosts sit in the United States. Another 5,100 sit in Germany. Those are production front ends, still reachable because Outlook on the web and Exchange Web Services were left open to the world years ago and nobody came back to prove the build.
That allow-from-any rule on 443 is an invitation with a TLS certificate. A WAF in front of OWA gets billed as threat-protection; it will still forward a replayed auth sequence if the application accepts it. Hybrid leftovers make this worse. The “we migrated to the cloud” slide rarely includes the on-prem box that still publishes EWS for a line-of-business app.
Treat those hosts the way you treat domain controllers. Mail, calendar, and a pile of internal apps still trust Exchange as identity glue. An unpatched auth bypass on that path is a tenant problem, not a mail-admin problem.
Capture-Replay Privilege Path From Stolen Auth to Mailbox
Capture-replay is a miserable class of bug for operators, because it walks around the controls you already run. Account lockouts. MFA prompts on interactive logon. Alerts aimed at brute-force and password spray. A replayed token or captured auth blob looks like a legitimate session coming back for another request. Threat detection tuned for failed logons stays quiet.
Read Microsoft’s wording the way an incident responder would. Authentication bypass by capture-replay, then privilege elevation over the network for an authorized attacker. Someone who can see or steal an auth exchange can come back with more rights than the original user. Mailbox access, impersonation, and the Exchange-to-directory hop that every incident response playbook already dreads.
You won’t firewall your way out of an unpatched auth bypass if mobile clients and Outlook on the web have to keep answering. You can shrink who is allowed to talk to those endpoints, put the front end behind a reverse proxy you actually log, and kill legacy auth so there is less material to capture. Security hardening here is boring on purpose: patch proof, protocol cutover, and source restriction.
Defense in depth on this CVE is a reject path. The patched build refuses the replay. The unpatched build turns a copied handshake into a privileged session. Everything else (lockouts, banner pages, “we have MFA”) is theater until the update is installed and you can show the build number.
IT Support Impersonation Turns Remote Sessions Into Token Capture
Same news cycle, different ticket, same credential problem. Microsoft Threat Intelligence documented a human-operated campaign that abuses Teams external collaboration to impersonate IT support, land a remote session, and drop a Node.js implant. The operators then move laterally with tools your environment already trusts. Malwarebytes, covering the consumer-facing cousin of that move, notes that tech support scams have left the fake-virus pop-up era. The enterprise version is a chat from “helpdesk” and a remote-assistance prompt.

A shared desktop is a capture window. Browser cookies, Outlook prompts, VPN reconnects, the Exchange session sitting in the tray. If someone can talk a user into Quick Assist, anydesk-class tools, or a “let me click through MFA for you” routine, capture-replay stops being a lab technique. It becomes a copy operation.
The real problem here is how your cyber security program splits these events. Helpdesk social engineering goes to awareness. Exchange patching goes to messaging. Nobody owns the join: an unpatched mail front end plus a remote session that can harvest the auth the CVE replays. Split tickets are how this sits for three weeks after a critical fix.
Federation and remote-assistance policy are the other half of the control set. External Teams contacts who can start a call that looks like IT, plus users who can install a remote tool without a privileged-access workflow, give the operator the packet they need. Pair that with 22,000 internet-facing Exchange boxes and you have a complete path from chat to mailbox.
Exchange Cybersecurity Containment: Patch Proof, Isolate, Hunt
Stop arguing about scan methodology and prove your own estate. Internet-wide counts are a hint. Your CMDB, your load balancers, and a port scan you ran yourself are the inventory. Include hybrid, lingering 2016 and 2019 boxes, and the “temporary” EWS publisher for that one vendor app.
Run these now, in order:
- Confirm the August 11, 2026 update (or a later SU that supersedes it) on every Exchange build you own; screenshot the build number into the ticket.
- If you cannot patch tonight, pull OWA and EWS off the public internet. VPN-only or a reverse proxy with an allowlist beats a hopeful WAF rule.
- Rotate credentials, app passwords, and session secrets for accounts that authenticated to those servers since August 11.
- Pull IIS and Exchange logs for repeated auth that has no matching interactive logon, then check mailbox audit for impersonation and unusual EWS.
After the immediate work, make the hunt durable. Inventory Exchange the way you inventory domain controllers: owner, build, internet exposure, and a named patch SLA. Require an out-of-band call to a known IT number before any remote support session starts, and keep remote-assistance tools off endpoints by default. Restrict Teams external access so a stranger cannot open a “helpdesk” thread that looks internal. Fold “helpdesk wants a remote session” into incident response as a privileged-access event, with the same containment you would use for a stolen laptop: session revoke, token replay search, mailbox and directory review.
Patch proof is the control that closes CVE-2026-62911. The rest keeps the next captured session from becoming enterprise-wide access while you argue about who owns the mail servers.
Sources
- Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
- Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
- Tech support scams look different now. Here’s what to watch for
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
