The Patch That Felt Like the End of the Job
An IT lead at a mid-sized German logistics firm applied Microsoft's August security update to the company's on-premises Exchange server the week it shipped, closed the ticket, and moved on to the next item in the backlog. That instinct, that patching once means the risk is handled, is exactly what the numbers published this week contradict. On August 31, 2026, three full weeks after Microsoft disclosed CVE-2026-62911 and shipped a fix, the security research group Shadowserver counted 21,899 internet-facing Exchange servers worldwide still running the vulnerable code.
The IT lead in this scenario patched. The problem was never people like him. It is the tens of thousands of servers nobody patched at all, and the fact that his own patched server sits on the same internet as every one of theirs.
What CVE-2026-62911 Actually Does
CVE-2026-62911 is an authentication bypass by capture-replay flaw, tracked under CWE-294, with a CVSS score of 8.0. Microsoft disclosed it on August 11, 2026, describing it as letting an attacker who can capture and replay authentication traffic impersonate a legitimate Exchange user and escalate privileges across the server. Microsoft shipped a patch the same day it disclosed the flaw. The Dutch national cyber security centre, NCSC-NL, reported the following week that public exploit code for the vulnerability was already circulating, which removes the last practical excuse for treating this as a low-urgency update.
The Exposure, By the Numbers
Shadowserver now runs a daily internet-wide scan and publishes a Vulnerable Exchange Server Report specifically so that national computer emergency response teams can track unpatched systems inside their own jurisdiction. Its August 31, 2026 count breaks down as follows:
| Country or region | Vulnerable Exchange servers |
|---|---|
| United States | approximately 6,200 |
| Germany | approximately 5,100 |
| Rest of world combined | approximately 10,600 |
| Worldwide total | 21,899 |
Germany's count is not a rounding error. It is the second-highest national exposure in the world, three weeks after the patch existed.
Why Germany Is the Number Worth Sitting With
Germany's Federal Office for Information Security, the BSI, put its own number on the same problem: roughly 85% of Germany's on-premises Exchange servers remain vulnerable to CVE-2026-62911. That is not 85% of servers that happen to be German; it is 85% of the entire German on-premises Exchange fleet still running exploitable code, in a country whose own domestic security agency is the one publishing the figure. For any organisation subject to NIS2's incident-reporting and duty-of-care obligations, an Exchange server compromised through a patch that has been public for three weeks is a hard conversation to have with a regulator, because the defence that the vulnerability was unknown or unpatchable does not apply here. The patch exists. Most of the fleet has not installed it.
What to Check Before You Close This Tab
An organisation running Exchange on-premises should treat this as a same-day check, not a backlog item: confirm the August 11, 2026 security update is installed on every on-premises Exchange server, not just the ones a change log says were touched, since multi-server environments are exactly where a patch quietly misses a box. Where the update cannot be applied immediately, restrict external access to Exchange management interfaces and monitor authentication logs for replay-style anomalies in the meantime. And treat Shadowserver's ongoing daily count, not this week's headline, as the thing to check again next month, because a number this large three weeks in does not fix itself on its own schedule.
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: Gunra Ransomware Runs on Fortinet Bugs Patched in 2025 | Your Older Macs Needed Seven Tries to Get Patched


