A critical authentication-bypass flaw in Microsoft Exchange Server, tracked as CVE-2026-62911, has moved from “patch available” to “actively exploitable” in the space of a few weeks. Microsoft fixed it in August’s Patch Tuesday update, but threat intelligence group Shadowserver reported that nearly 22,000 Exchange servers worldwide remain unpatched and reachable from the open internet. Working exploit code is now publicly available, which means the barrier to attack has dropped from “requires research” to “copy and paste.”
This matters directly to UK SMEs because Exchange Server, the on-premises version rather than the cloud-hosted Microsoft 365 mailbox, is still common in businesses that run their own mail server, often for compliance reasons or because migrating away from it has simply never made it to the top of the to-do list. If that’s your business, or your IT provider manages Exchange on your behalf, this is not a “get to it eventually” patch.
What the flaw actually does
CVE-2026-62911 is an authentication bypass affecting Exchange Server 2016, 2019, and the Subscription Edition, with a CVSS severity score of 8.0. In practice, successful exploitation lets an attacker with only basic access take over every mailbox on the affected server, reading and sending email, downloading attachments, and using the compromised account to launch further attacks, including convincing invoice fraud or phishing sent from a real, trusted internal address. National cybersecurity agencies have confirmed exploit code is circulating, so this is no longer a hypothetical risk being flagged out of caution.
What to check this week
Two questions settle whether this affects you. First: does your business, or your IT provider, run an on-premises Exchange server at all? If everything is on Microsoft 365 cloud mailboxes with no on-premises hybrid setup, this specific flaw doesn’t apply, though it’s still worth confirming that assumption rather than guessing it. Second, if you do run Exchange on-premises: has the August Patch Tuesday update actually been applied, and is the server reachable directly from the internet? If patching isn’t possible immediately, guidance from national cybersecurity agencies is blunt: take the server offline from public internet access until it is patched, rather than leaving it exposed while you wait.
If your email is managed by an outsourced IT provider, this is a one-line email worth sending today: “Are we running on-premises Exchange, and if so, is CVE-2026-62911 patched?” A confident, specific answer is reassuring. A vague one is a reason to ask again, more precisely, or to get an independent check. This is exactly the kind of blind spot that ongoing monitoring from a service like KeepSafe is designed to catch, flagging exposure on systems you or your provider may have quietly assumed were fine.
Why this keeps happening
This is now a familiar pattern on this site: a vulnerability gets disclosed and patched, attention moves on within days, and weeks later exploitation catches up with whoever didn’t act on the first warning. The gap between disclosure and mass exploitation used to be measured in months. For flaws like this one, it’s now measured in weeks, sometimes less once exploit code goes public. Businesses that treat a patch Tuesday alert as background noise rather than an action item are the ones still exposed a month later, which is precisely the group these 22,000 unpatched servers now represent.
The takeaway
If you know your business runs on-premises Exchange, confirm today that August’s patch for CVE-2026-62911 is installed, and that the server isn’t sitting exposed to the open internet in the meantime. If you’re not sure whether you run it, that uncertainty is itself worth resolving this week, not after the next headline about it being used in a live attack.