Key points
- 382 Australian and 56 New Zealand Exchange servers remain vulnerable to CVE-2026-62911 as of August 31, three weeks after Microsoft’s fix.
- Working exploit code is now publicly available, and NCSC-NL warns an unauthenticated attacker could potentially achieve arbitrary code execution.
- ASD is urging organisations still running legacy Exchange versions to act, or segment networks if replacement isn’t possible.
Unpatched and ancient Microsoft Exchange servers that are vulnerable to a critical authentication bypass vulnerability are rife on Australian and New Zealand networks, putting organisations’ mailboxes in risk of full compromise.
Worse, there is now working exploit code publicly available for the vulnerability.
Security monitoring nonprofit ShadowsServer Foundation counted 382 Australian and 56 New Zealand Exchange servers still vulnerable to CVE-2026-62911 as of August 31, three weeks after Microsoft released a fix.
The affected versions are the older Exchange Server 2016, 2019, and Subscription Edition, which compound the patching problem.
Exchange 2016 and 2019 now receive security updates only through Microsoft’s Extended Security Updates (ESU) program.
This means organisations running those versions are paying for continued support on infrastructure they have not yet replaced or migrated to cloud-hosted Exchange.
The Netherlands’ National Cyber Security Centre (NCSC-NL) said on August 28 that proof-of-concept exploit code had appeared online.
NCSC-NL upgraded its advisory and warned that an unauthenticated attacker could potentially achieve arbitrary code execution.
Microsoft has not yet confirmed active exploitation in the wild, and the flaw does not yet appear in the United States Cybersecurity and Infrastructure Agency’s Known Exploited Vulnerabilities (CISA-KEV) catalogue.
The flaw is rated as CVSS 3.1 score of 8 out of 10, and allows an attacker to intercept authentication traffic and replay it to gain elevated privileges on an Exchange server.
Microsoft said a successful attacker “would be able to take control of the mailboxes of all Exchange users” and could send, read and download attachments from any account on the system.
The vulnerability was discovered by Orange Tsai of the DEVCORE Research Team during the Pwn2Own Berlin 2026 contest.
Asked about the vulnerability by iTnews, the Australian Signals Directorate (ASD) encouraged organisations still running legacy Exchange to act.
“Legacy technology that can no longer receive important security updates and patches are an easy target for malicious actors and are more vulnerable to cyberattacks,” an ASD spokesperson said.
The directorate also advised that where legacy systems cannot be replaced, organisations should segment networks to protect their most critical systems, ASD added.
ASD maintains standing guidance on Exchange Server security hardening and end-of-support planning.
Globally, ShadowServer counted 21,899 vulnerable Exchange servers as of August 31 2026, suggesting the slow patching and upgrading isn’t unique to the Oceania region.

