CVE-2026-62911: 22,000 Exchange Servers Still Unpatched
A September 2026 scan found roughly 22,000 internet-facing Exchange servers still running a version affected by CVE-2026-62911. No exploitation of this specific flaw has been observed yet, but since November 2021 CISA has added 20 Exchange vulnerabilities to its Known Exploited Vulnerabilities catalog, 14 of them tied to ransomware.
- About 22,000 Exchange servers remain vulnerable to CVE-2026-62911
- Germany was the highest-risk region in the scan sample
- CISA has added 20 Exchange flaws to its KEV catalog since November 2021
- 14 of those 20 flaws were linked to ransomware activity
Read next
Security