A serious vulnerability was recently discovered in Exchange Server 2016, Exchange Server 2016, and Exchange Server Subscription Edition (SE). The vulnerability is designated CVE-2026-62911 and can be exploited by hackers to gain full access to affected systems, according to Bleeping Computer. Microsoft has released security patches to address the vulnerability as part of its August 2026 Patch Tuesday release, but there are still 21,899 unpatched servers at risk, according to The Shadowserver Foundation. The highest concentrations of vulnerable servers are in the US and Germany, the security group said. The Netherlands National Cyber Security Centre and other agencies have urged admins to install the latest patches as soon as possible. This article originally appeared on Computer Sweden. Related: Exchange CU1 delayed further as Microsoft races to verify AI-found flaws Microsoft Exchange Server on prem gets a little harder to use Is it time to move to hosted Exchange? Considerations for IT
Back to Technology
Technology
September 3, 2026 at 5:20 PM
Serious vulnerability threatens tens of thousands of Exchange servers
Computerworld