Security3 distinct publishers3 min readPublished
Microsoft patched the Exchange authentication bypass on August 11. Shadowserver's September 1 scan still counts 21,899 internet-facing servers unpatched, and NCSC-NL says working exploit code for full mailbox takeover is circulating.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Capture-replay is the mechanism. It sets the entry price. Microsoft's wording is that an authorized attacker elevates privileges over a network [3], and BleepingComputer's read of the advisory adds low attack complexity plus a user interaction requirement, with the attacker holding basic privileges on the target [6]. Exploitation starts from a foothold, not from a blank internet scan. The payoff is what makes that foothold worth buying: read and send access across every mailbox on the server, attachments included [4].
The counting deserves care, because two numbers are being read as one. Shadowserver counts IP addresses carrying an Exchange fingerprint that are unpatched and reachable [9]. The United States and Germany contribute 6,200 and 5,100 [11], which is 11,300 between them, or 51.6 percent of the total [1]. Germany's BSI posted on August 28 that about 85 percent of the country's on-premises Exchange servers remain vulnerable [14], a measurement of all installs rather than the internet-facing subset. Forcing the two together would put Germany's exposed fleet near 6,000 [3]; the numbers add up, but they are counting two different populations.
The timeline matters too. From the August 11 fix [1] to Shadowserver's September 1 figure [10] is 21 days [2]. Exchange 2016 and 2019 receive these updates only through the Period 2 ESU program, which stops shipping in October 2026 [15]. That is roughly two months after this patch [4], so for two of the three affected versions the patch route closes well before the unpatched population is likely to move. NCSC-NL writes its guidance on that assumption, telling 2016 and 2019 operators to keep the server reachable only internally and to replace it where possible [16].
Zscaler's post on the bug, which recommends its own private access product [19], hangs the urgency on frontier AI models generally and on its own report's claim that mean-time-to-exploit has gone negative [19]. That framing borrows its urgency from Zscaler's broader trend claims rather than from anything confirmed about this specific bug. NCSC-NL says working exploit code is already circulating [12], Microsoft's advisory has not confirmed it [12], and CISA had not reported in-the-wild exploitation at the time of Zscaler's writing [13]. The operative question is who already holds a low-privilege mailbox on one of these servers rather than who can write the exploit, and OWA needing to be reachable by design keeps that population large [20].
The campaign history is the reason to read the gap as a schedule rather than a severity score. CISA has added 20 Exchange Server vulnerabilities to its Known Exploited Vulnerabilities catalog since November 2021, 14 of them also flagged as abused in ransomware [17]. The most recent, CVE-2026-42897, was exploited in cross-site scripting attacks against Outlook Web Access users and patched in June [18].
Ranked by verification strength, evidence, and original report placement.
Microsoft released the fix for CVE-2026-62911 on August 11, 2026, as part of the August 2026 Patch Tuesday.
Shadowserver warned on Tuesday that 21,899 IP addresses with a Microsoft Exchange Server fingerprint remain unpatched and exposed online.
As of September 1, Shadowserver had identified around 22,000 Exchange servers still unpatched and exposed to the internet.
Of the unpatched exposed servers, roughly 6,200 are in the United States and 5,100 in Germany.
NCSC-NL reported that working exploit code for CVE-2026-62911 is already available online, and Microsoft has not updated its advisory to confirm this.
Exchange Server 2016 and 2019 are out of support; only customers enrolled in the Period 2 Extended Security Update program receive updates released between May and October 2026, and ESU ends in October 2026.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
1 article · September 2, 2026
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
security
ONCD stakes Texas water security on six months of donated vendor red teaming4 distinct publishers
security
CISA's KEV clock now runs on BOD 26-04, and your patch SLA cites the wrong directive2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Three accounts, two measurements
Underneath the three reports sit only two independent observations: Shadowserver's daily scan and NCSC-NL's bulletin. Everything about the flaw itself — capture-replay, mailbox takeover, CVSS 8.0 — is Microsoft's own advisory, relayed almost word for word by BleepingComputer and Help Net Security and relayed again by Zscaler. The most alarming fact in the story, that working exploit code is already public, has exactly one source, and Microsoft has pointedly not confirmed it.
The fix is visible mainly by its absence
Twenty-one days after August 11, Shadowserver could still fingerprint 21,899 exposed servers, and BSI's Mastodon post puts roughly 85 percent of German on-premises Exchange in the vulnerable column. The vulnerability's footprint is measured well; uptake of the remedy is what nobody can show. For Exchange 2016 and 2019 the arithmetic gets worse — only Period 2 ESU enrollees can apply the patch at all, and that door closes in October.
Sober numbers, loud adjectives
The counts are careful and the qualifiers are not. Microsoft's score is 8.0; Zscaler and BleepingComputer read that as high-severity while Help Net Security prints critical in its headline. Nobody has shown exploitation in the wild — Zscaler says so outright, the hijack framing elsewhere does not — and the requirement for user interaction, which tempers the whole scenario, survives in only one account. Small overshoot, but it all leans the same way, and the largest lean is the vendor post's claim that AI has already made patching futile.
One account sells the remedy it recommends
Zscaler's post is a competent administrator advisory that resolves into a catalogue — Private Access, Clientless Access, AppShield, DLP, Deception, workload segmentation — and its central timing argument cites Zscaler's own ThreatLabz report. Its most striking line, that the bug is 'effectively not exploitable' behind the product regardless of patch state, is a sales claim wearing engineering clothes. The trade reports are cleaner but not disinterested: BleepingComputer's page ends in a pitch for a sponsor's simulation report, and the research credit runs through Trend Micro's Zero Day Initiative.
Firm on the numbers, soft at the edges
The patch date, affected builds, impact and scan counts are mutually consistent across all three accounts, so the spine of the story holds. What wobbles is at the margins: the exploit-code report has one source and no vendor confirmation, the AI-acceleration argument is self-cited, BSI's 85 percent arrives without a denominator, and the dates given for the earlier CVE-2026-42897 — fixed in June, catalogued as exploited on May 15 — cannot both be read the ordinary way. None of that undermines the exposure finding; it does mean the chronology around it deserves a second look.