-
A cybersecurity group says almost 22,000 Microsoft Exchange servers still miss a critical fix.
-
The flaw lets attackers slip into mailboxes without needing a password at all.
-
Working attack code is already public, and it is easy for hackers to copy.

Nearly 22,000 Microsoft Exchange servers around the world are still missing a key security update. That warning comes from Shadowserver, a nonprofit group that scans the internet daily for weak systems.
According to a post from International Cyber Digest on X, the group flagged the exposed servers on August 28, 2026. The bigger worry is that a working exploit already sits in public view, so attackers do not need special skills to use it.
How Shadowserver Tracks the Exposed Servers
Shadowserver runs full scans of the internet every day. It checks Microsoft Exchange servers for a long list of known security holes. Its latest vulnerable Exchange server report tracks flaws going back to 2020, including newer ones added this year. Two of the freshest additions are CVE-2026-42897 and CVE-2026-62911, both added to the watch list in 2026.
The group also flags servers running outdated software versions. These old builds, called end-of-life versions, no longer receive security patches from Microsoft at all. Shadowserver marks these systems separately, since they carry ongoing risk even without a single named flaw. Anyone running Exchange can check their exposure through the Shadowserver Dashboard, which lists results by country, network, and specific vulnerability.
Reactions on X show real concern from the security community. One user, posting as @gdlinux, called the number of unpatched servers concerning. They pointed out that the exploit is public and reportedly simple to use, so there is little reason to delay patching. Another user, posting as @x_PuraVida_x, noted an important distinction.
The report covers self-hosted Exchange servers that companies run on their own hardware, not Microsoft’s cloud-based Exchange Online service. That difference matters, since cloud users are not part of this exposure count.
Why an Unpatched Mailbox Flaw is So Dangerous
The core danger here is simple. A flaw that skips the password step gives attackers a direct path into someone’s inbox. Once inside, they can read private messages, steal contacts, or launch further attacks from a trusted account. Mailboxes often hold sensitive files, financial details, and login resets for other services. That makes email systems a favorite target for criminals.
The financial scale of cybercrime is staggering. A Global Ledger investigation found that Russian-language darknet markets processed approximately $1.85 billion through licensed crypto exchanges between January and September 2025, with five major platforms MEGA, Kraken, BlackSprut, and Nova- routing funds through at least 20 exchanges holding over 130 international licenses.
Public exploit code raises the stakes even higher. When attack instructions are freely available online, criminals do not need deep technical knowledge to use them. A user posting as BullBear.News warned that public proof-of-concept code often leads to automated mass scanning within hours. Bots can search the entire internet for vulnerable servers and strike before defenders even notice.
Some reactions on X leaned skeptical or joked about the situation. A user posting as YogSoth0 remarked that since the software runs on Windows, the news would likely draw attention regardless.
Another user, Armtesttom, questioned why organizations still run Exchange on their own premises today. These comments reflect a wider debate about whether companies should keep managing email servers themselves or move fully to cloud platforms.
Shadowserver’s report also lists which Exchange versions count as vulnerable for specific flaws. For one 2024 flaw tracked as CVE-2024-21410, any version older than build 15.2.1118.12 or 15.1.2507.12 gets flagged as vulnerable.
Versions at or just above those numbers may already have protections in place, though Shadowserver still tags them for review. This kind of detail helps administrators figure out exactly where their systems stand.
Steps Exchange Administrators Should Take Now
The fix here is direct. Anyone running Microsoft Exchange should check their server version right away. Compare it against the vulnerable ranges listed in Shadowserver’s report or check Microsoft’s own update guide for specific CVE details. If a server matches an old, unpatched build, install the latest update immediately.
One X user, posting as LiteManager, kept the advice short and to the point, simply urging everyone to install their updates. That basic step protects against most of the flaws on Shadowserver’s list. Organizations still running end-of-life Exchange versions should treat this as urgent, since those systems get no further security fixes from Microsoft at all.
Government agencies have also weighed in on related Exchange flaws. The U.S. Cybersecurity and Infrastructure Security Agency previously issued a directive requiring federal agencies to apply mitigations for a related hybrid Exchange flaw. That kind of guidance shows how seriously security experts treat these unpatched mailbox risks.
Administrators can also use Shadowserver’s dashboard to search their own network for exposure, filtering results by specific CVE tags. Doing this regularly, rather than waiting for a breach, gives IT teams a real head start.
As several voices in the security community pointed out this week, patching Exchange servers quickly remains the simplest and most effective defense against these ongoing attacks.