CVE-2026-62911 Leaves 21,899 Exchange Exposed
A public PoC for CVE-2026-62911 shows an attack chain that can end in RCE and SYSTEM on Exchange, with 21,899 servers still vulnerable.
Nearly 22,000 Microsoft Exchange servers exposed on the internet remained unpatched against CVE-2026-62911, while a public proof of concept showed an attack chain that can lead to unauthenticated remote code execution and SYSTEM-level control. Available data places 21,899 vulnerable IP addresses, with the highest concentrations in the United States and Germany.
Nearly 22,000 Microsoft Exchange servers exposed on the internet remained unpatched against CVE-2026-62911, according to BleepingComputer, while a public proof of concept showed an attack chain that can lead to unauthenticated remote code execution and SYSTEM-level control. The surveys cited by Shadowserver and other coverage place 21,899 vulnerable public IP addresses, with the largest concentrations in the United States and Germany.
What did the public PoC show?
The public proof of concept showed an attack chain that, according to Devel Group's technical writeup, can lead to unauthenticated RCE and SYSTEM-level control over Exchange. CyberPress and Decryption Digest said that, based on Microsoft's advisory and ZDI, the flaw on its own is not classified as a pure pre-auth RCE.
The scenario described combines an authentication bypass with NTLM relays to MRSProxy and WCF calls that can write ASPX files accessible through IIS. Decryption Digest also described a four-stage automation focused on MRSProxy, with NTLM coercion, relay to the HTTP.sys endpoint, abuse of replication operations, and writing ASPX web shells.
SOC Prime added that the attack can abuse NTLM relay, MRSProxy, and ASPX web shell writing. It also said the access can gain machine account privileges, and that the MRSProxy endpoint hosted on HTTP.sys accepts Negotiate authentication without properly validating channel bindings, which makes it easier to relay machine account hashes and gain authorized access to the MailboxReplicationProxyService.
How many servers were still exposed?
Available data points to 21,899 Microsoft Exchange servers still exposed to CVE-2026-62911, a figure that matches counts based on Shadowserver and refines the broader headline of nearly 22,000 vulnerable systems.
Shadowserver Foundation added CVE-2026-62911 to its scans of Exchange exposed on the internet on August 27, 2026. In later reports cited by Rocket Boys Security Measures Lab, the largest concentration appeared in the United States, with about 6,200 vulnerable public IPs, and in Germany, with about 5,100.
BleepingComputer reported that nearly 22,000 Microsoft Exchange servers exposed on the internet were still unpatched against the vulnerability. An additional analysis by Gblock put the figure at 21,899 and noted that the number is based on Shadowserver counts of vulnerable public IPs.
Which versions were protected?
Microsoft and the CVE records identify the minimum fixed builds as Exchange Server 2016 CU23 version 15.1.2507.72, Exchange Server 2019 CU14 version 15.2.1544.44, Exchange Server 2019 CU15 version 15.2.1748.49, and Exchange Server Subscription Edition RTM version 15.2.2562.46.
GBHackers published those numbers in its coverage of the CVE-2026-62911 PoC, and the reference matches the Microsoft advisory cited in technical summaries. At the same time, specialist coverage stressed that the issue remains an authentication bypass, even if the technical chain can end in broader server compromise.
A secondary source, CybersecurityNews, also said the vulnerability affects many servers, with higher concentrations in the United States and Germany. That claim was not backed by a verifiable methodology in the results provided, so it can only be treated as an unconfirmed reference.
Sources
- CVE-2026-62911 Microsoft Exchange Pre-Auth RCEdecryptiondigest.com· Decryption Digest
- Prueba de Concepto Pública Expone RCE sin autenticación en Exchange Server CVE-2026-62911devel.group· Devel Group
- Nearly 22000 Microsoft Exchange servers vulnerable to hijack attacksbleepingcomputer.com· BleepingComputer
- CVE-2026-62911: Microsoft Exchange Capture-Replay Authentication Bypasspenligent.ai· Penligent
- CVE-2026-62911 Exchange Server Pre-Auth RCEsocprime.com· SOC Prime
- Exchange Servers CVE-2026-62911 Remain Exposedcybersecuritynews.com· CybersecurityNews
- 21,899 Exchange Servers Still Open to Mailbox Hijackgblock.app· Gblock
- PoC Released for Microsoft Exchange CVE-2026-62911gbhackers.com· GBHackers
- Microsoft Exchange ServerのCVE-2026-62911、PoC公開で警戒高まる 約2万2,000台が未更新と報道rocket-boys.co.jp· Rocket Boys Security Measures Lab
- Public PoC Released for Microsoft Exchange Pre-Auth Remote Code Execution Chaincyberpress.org· CyberPress



