Affected Systems
Microsoft Exchange Server 2016, 2019, and Subscription Edition (SE). Approximately 21,899 internet-exposed servers remain unpatched globally, with 6,200 in the US and 5,100 in Germany. Exchange 2016/2019 require Extended Security Updates (ESU) program access for patches.
Exploitation Status
Public exploit code is available online (confirmed by NCSC-NL). No confirmed active exploitation reported yet, but exploit complexity is low and requires only basic privileges plus user interaction.
Business Impact
Attackers with basic server privileges can hijack all user mailboxes via authentication bypass (capture-replay). Full mailbox takeover enables reading emails, sending emails as users, and downloading attachments. High risk for organizations with internet-exposed Exchange servers, especially those running end-of-support versions (2016/2019) without ESU coverage. Germany's BSI reports 85% of on-premises Exchange servers in Germany remain vulnerable.
Urgency
🟠Within 24 hours
Recommended Actions
- Apply Microsoft's August 2026 Patch Tuesday updates for Exchange Server 2016, 2019, and SE immediately. Verify ESU program enrollment for 2016/2019 versions.
- Identify all internet-exposed Exchange servers using Shadowserver or internal scanning. Restrict Exchange Server 2016/2019 to internal network access only if patching is not immediately possible.
- Monitor Exchange logs (IIS logs, Exchange Admin Audit logs) for unusual authentication patterns, privilege escalation attempts, or mailbox access anomalies.
- Prioritize migration from Exchange 2016/2019 to Exchange SE or Exchange Online, as ESU support ends October 2026.
- Implement multi-factor authentication (MFA) for all Exchange user accounts and administrative access to reduce credential-based attack surface.
