Exchange Servers Leave Mailboxes Open to Hijack

BleepingComputer reports that nearly 22,000 internet-exposed Microsoft Exchange servers remain unpatched for two flaws, including CVE-2026-62911, an authentication bypass that can let an attacker hijack mailboxes, and CVE-2026-42897, a cross-site scripting bug. The scale matters because the affected servers are still reachable from the internet. The bypass is the bigger problem: once an attacker gets past Exchange's login check on the server, the server can treat them as already authenticated and let them operate across the mailboxes it serves. That means the compromise can sit at the Exchange layer instead of looking like a single stolen account, which makes account-only monitoring easier to miss. For organizations that put a shared Exchange server between users and their mail, the exposure is tenant-wide until the server is fixed. The second flaw adds to the patch burden, but the main risk here is the trust boundary itself: one exposed server can stand in for many mailbox identities at once.

Part of the PlainSec briefing for 2026-09-03

Every edition of this story: Exchange Servers Leave Mailboxes Open to Hijack

Sources