Hundreds of Old, Vulnerable Exchange Servers Remain in Australia
iTnews reports that ShadowServer counted 382 Australian and 56 New Zealand Exchange servers still vulnerable to CVE-2026-62911 as of 31 August โ three weeks after Microsoft's fix for an unauthenticated authentication-bypass that allows an attacker to take control of every mailbox on the server.
| Attribute | Detail |
|---|---|
| Affected servers | 382 AU / 56 NZ (Shadowserver, 31 Aug) |
| Flaw | CVE-2026-62911 (unauthenticated auth bypass) |
| PoC | Public working exploit code; NCSC-NL warns of arbitrary code execution |
| ASD guidance | Patch or segment legacy Exchange 2016/2019/Subscription Edition |
| Source | iTnews โ Tier 3/4 |
Working proof-of-concept code is now public, and the Netherlands' NCSC-NL upgraded its advisory to warn an unauthenticated attacker could achieve arbitrary code execution, though Microsoft has not confirmed in-the-wild exploitation and the flaw is not yet in the CISA KEV catalogue. The ASD noted legacy Exchange is an easy target and urged organisations to patch or, where replacement is not possible, segment legacy networks. Lands directly in the ASD ISM / ACSC Essential Eight remit (patching, internet-exposure control) and should prompt a mailbox-compromise notification assessment under the OAIC Notifiable Data Breaches scheme.
Related Pages
- Cve 2026 62911 โ the underlying vulnerability