VulnerabilityBleeping Computer
8.0 — CRITICAL
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Nearly 22,000 Microsoft Exchange servers remain unpatched against a high-severity authentication bypass vulnerability, allowing attackers to hijack user mailboxes and perform low-complexity attacks with basic privileges.
⚙️Technical Details
CVEs
CVE-2026-62911CVE-2026-42897
Affected Systems
Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition
Attack Vectors
NETWORK
💥Impact Assessment
Severity: HIGH
Who Is at Risk
Users of unpatched Microsoft Exchange servers, particularly those in the United States and Germany.
🛡️Recommended Actions
1Apply patches to affected systems as soon as possible
2Restrict access to Microsoft Exchange servers to internal networks only
3Monitor for suspicious activity on vulnerable systems
📦Affected Products
Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition
🔐NVD Verified DataVERIFIED
CVE-2026-62911 ↗CVSS 8 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HWeaknesses
CWE-294
Affected Products (CPE)
Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition
CVE-2026-42897 ↗CVSS 6.1 — MEDIUM
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NWeaknesses
CWE-79
Affected Products (CPE)
Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
