The National Cyber Security Center warns organisations about multiple serious vulnerabilities in Microsoft Exchange Server. Especially CVE-2026-62911 requires attention. Public proof-of-concept code has been published for this vulnerability. The NCSC assesses both the risk of abuse and the potential damage as well as high.
What Exchange versions are vulnerable?
CVE-2026-62911 allows an attacker to execute malicious code without valid remote login data. According to the NCSC, this can lead to access to email accounts and further attacks within the network.
Other vulnerabilities from the same update may disrupt the email service, take over user accounts, provide higher access rights and access sensitive information.
- Microsoft Exchange Server 2016
- Microsoft Exchange Server 2019
- Microsoft Exchange Server Subscription Edition
Check today which Exchange version you are using, whether the August updates are installed and how the successful installation has been verified.
Why this warning is now particularly important
The security update for CVE-2026-62911 appeared earlier in August. The situation changed when publicly available exploit code appeared.
Once technical information and working exploitation code become available, it becomes easier for attackers to use a vulnerability practically. The period between publication, availability of a patch and active abuse may therefore be short.
An organisation must be able to identify, prioritize, install and then check critical security updates. A general commitment by a supplier that patches are executed gives too little certainty.
- which systems within the organisation may be vulnerable
- who assesses security warnings
- which time limit applies to urgent patches
- who can authorise an emergency change
- how to check whether installation has actually been successful
- how exceptions and delayed patches are recorded
Exchange 2016 and 2019 require extra attention
Microsoft Exchange Server 2016 and 2019 are at the end of their regular support and receive security updates only through the Extended Security Updates program.
The NCSC recommends organisations that do not have a supported environment to make these servers accessible only from internal networks and phase them out where possible.
Do you use Exchange via an external IT service provider? Ask which Exchange version is used, whether the August security updates are installed and how this was checked. A demonstrable patch status of the system in question gives more certainty than the general notification that patching is being performed.
The broader lesson: patch management must be organized
This Exchange vulnerability is a current example of a structural issue. New vulnerabilities are constantly appearing. Some pose hardly any direct risk, while others become practically abuseable within a few days.
Good patch management ensures that these differences are recognised and serious vulnerabilities are addressed quickly enough. Technique, processes, responsibilities and control are part of this.
Sources and deepening
Based on official frameworks and practical implementation
The source pages provide the formal background. Kynexis Information Security translates this information into an executable approach for your organisation, sector and risk profile.


