Security researchers have identified nearly 22,000 Microsoft Exchange servers accessible online that lack patches for a critical authentication bypass flaw. The vulnerability allows attackers to gain control over all user mailboxes hosted on affected on-premises instances.
What happened
Microsoft issued a security update in August 2026 to address the flaw, which carries a high severity rating. Despite the patch’s availability, scans conducted in late August revealed that approximately 22,000 servers remain exposed. The vulnerability does not require user interaction, enabling attackers to bypass authentication mechanisms and access mailbox data directly.
No evidence has emerged of active exploitation in the wild, though the unpatched servers present a significant risk. Microsoft has not disclosed whether the flaw affects Exchange Online or hybrid deployments.
What we don’t know yet
The total number of organizations operating the unpatched servers remains unclear. Additionally, Microsoft has not provided details on the timeline for patch deployment or whether automated mitigation tools are available for affected environments.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 1 Sep 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story No prior coverage of this specific Exchange server vulnerability count.
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=489 slug=22-000-exchange-servers-unpatched-against-hijack-flaw quick_read=1
-
Editor review — Approved
- Score: 85/100
- Factual grounding: The draft states the patch was issued 'in August 2026,' but the source only says 'August' without specifying the year. While the reference date is 1 September 2026, the source publication date is the same day, and the source does not confirm the patch year. Omit the year or clarify if the source implies 2026.
- Style compliance: The standfirst ('Microsoft warns of high-severity authentication bypass in on-prem Exchange') is not directly supported by the source. The source does not attribute the warning to Microsoft
- it reports the vulnerability as identified by researchers. Rephrase to reflect the source's framing.
- Quote integrity: No blockquotes are used in the draft, but the phrasing 'Security researchers have identified' closely mirrors the source's opening line. While not a verbatim copy, the structure is too similar. Rephrase to avoid echoing the source.
- Audience relevance and notability: The draft does not explicitly state whether the 22,000 servers are globally distributed or concentrated in specific regions. While the source implies global exposure, adding this detail (if available) would improve relevance for a global audience.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Rejected library image #27: The candidate's alt text ('nvidia blackwell gpu server rack data center') and query ('Microsoft Exchange server rack setup') are mismatched, and the image does not depict Microsoft Exchange infrastructure or vulnerabilities. The relevance to the article topic (Exchange server vulnerabilities) is nonexistent, and no other candidate was provided to evaluate.
- Assigning hero image — Reused library image reused image #58
- Linking related stories — Linked 3 relations from 423 candidates
- Publishing — Published 22-000-exchange-servers-unpatched-against-hijack-flaw
- Mastodon — Posted https://mstdn.social/@hostingpaper/117196113931432841




Discussion · coming soon
Be the first to join the thread when community discussion launches.