22,000 Exchange Servers Are Still Exposed to a Live Hijack Flaw; And the Clock Is Running Out
A live, actively targetable flaw in on-premises Microsoft Exchange is sitting unpatched on roughly 22,000 servers worldwide and for many small and mid-size businesses, the safety net (extended security support) runs out next month, turning a patching task into a hard deadline.
If your business still runs its own on-premises Microsoft Exchange server for email, this week's security news deserves more than a passing glance. Researchers tracking a critical authentication-bypass vulnerability, cataloged as CVE-2026-62911, have found that nearly 22,000 Exchange servers worldwide — over 6,000 of them in the United States — remain unpatched and exposed to attack, even though Microsoft shipped a fix back in August.
The flaw allows an attacker to bypass authentication through an NTLM relay technique, effectively letting them take over mailboxes without ever needing a valid password. For a business, that means an attacker could read internal communications, harvest contacts and credentials, send convincing phishing emails from a trusted internal address, or use compromised mailboxes as a launchpad deeper into the network. It's the kind of foothold that regularly turns into a full ransomware incident.
Why this is an SMB problem, not just an "enterprise IT" problem
It's tempting to assume vulnerabilities like this mostly threaten large corporations with sprawling server farms. In practice, the opposite is often true. Larger enterprises typically migrated to cloud email (Microsoft 365 or Google Workspace) years ago and employ dedicated patch-management teams. Small and mid-size businesses are far more likely to still be running an on-premises Exchange server that was set up years ago, is rarely touched unless something breaks, and doesn't have anyone actively monitoring Microsoft's monthly security bulletins.
That combination, older, unmaintained infrastructure plus limited in-house IT oversight, is exactly what attackers scan the internet looking for. Automated tools can identify vulnerable Exchange servers in minutes, and threat actors don't need to specifically target your company to become a victim; being an easy, unpatched target is enough.
There's also a second deadline stacked on top of this one. Extended Security Updates for Exchange Server 2016 and 2019 are scheduled to end in October 2026. Once that support window closes, even businesses that have kept up with patches will stop receiving fixes for newly discovered vulnerabilities altogether meaning the pressure to modernize isn't just about this one flaw, it's about what happens the next time a similar issue is found.
A pattern, not an isolated incident
This Exchange exposure didn't happen in a vacuum. It's part of a broader theme security researchers have been flagging all week: attackers are moving faster, and the tools available to them are getting better. Google issued an emergency patch for its sixth actively exploited Chrome zero-day of the year, underscoring that even everyday software your team uses constantly can quietly become an attack vector. Separately, threat-intelligence researchers reported that autonomous AI-driven attack tools have been used to fully compromise a network in under 10 hours automating reconnaissance, credential theft, and lateral movement at a pace that used to take skilled human attackers days or weeks.
Put together, the message for any resource-constrained IT environment is consistent: the gap between "vulnerability disclosed" and "vulnerability exploited" keeps shrinking, and manual, occasional patching is no longer a reliable defense on its own.
Where compliance fits in
If your business operates under any kind of regulatory framework, this isn't just an operational risk — it's a compliance one too. Timely patch management is an explicit expectation under the HIPAA Security Rule's risk management requirements, is directly reflected in the NIST Cybersecurity Framework's "Protect" function, and maps to several safeguards in the CIS Controls (notably Control 7, Continuous Vulnerability Management). For businesses in the defense supply chain, unpatched, internet-facing systems are precisely the kind of finding that can undermine a CMMC or NIST 800-171 self-assessment. An unpatched Exchange server isn't just a technical liability sitting on a network diagram — it's the kind of gap that shows up in an audit, a cyber-insurance questionnaire, or a breach investigation, and it's hard to explain away after the fact.
What SMBs should do this weekThe good news is that the fix here is well understood, even if it requires some deliberate follow-through:
First, confirm whether your organization runs on-premises Exchange Server 2016, 2019, or Subscription Edition, and verify that the August 2026 security updates addressing CVE-2026-62911 have actually been installed not just scheduled. If you're not certain, that uncertainty is itself the finding worth acting on.
Second, treat the upcoming end of Extended Security Updates as a planning deadline, not a someday item. Businesses still on Exchange 2016 or 2019 should be actively evaluating a migration path to a supported platform, whether that's a newer on-premises version or a move to cloud-hosted email, before the support window closes in October.
Third, use this as a prompt to check whether your broader patch-management process is proactive or reactive. If vulnerabilities are only addressed when someone happens to notice a headline, that's a process gap worth closing with routine vulnerability scanning and a defined patching cadence the kind of practice that satisfies both good security hygiene and the documentation regulators and auditors want to see.
Finally, don't treat this as an isolated Exchange problem. Given the same week's Chrome zero-day and AI-accelerated attack activity, it's worth confirming that browsers, endpoint agents, and other frequently overlooked software are on the same disciplined patch cycle.
The bottom line
Twenty-two thousand exposed servers is a big number, but the more important number for any individual business is one: is yours among them? For SMBs without a dedicated security team, this is exactly the kind of question a managed IT or cybersecurity partner exists to answer quickly, before it becomes a much more expensive question to answer after an incident.
Related Resource
