What Happened
Nearly 22,000 internet-facing Microsoft Exchange servers remain unpatched against CVE-2026-62911, an authentication-bypass-by-capture-replay flaw with a CVSS score of 8.0. The vulnerability sits in the MRSProxy endpoint, which fails to enforce Extended Protection for Authentication, opening a path for an attacker who already holds basic privileges on the target server to relay captured NTLM credentials and escalate into full control of any mailbox. Exploitation requires user interaction and low attacker complexity, and DEVCORE researcher Orange Tsai reported the flaw to Microsoft. The Netherlands’ National Cyber Security Centre says exploit code for the vulnerability now circulates publicly, though Microsoft has not confirmed active exploitation in the wild. Scans as of August 31 counted 21,899 unique vulnerable IP addresses, led by the United States with roughly 6,200 instances and Germany with about 5,100. Affected products include Exchange Server 2016, 2019, and Subscription Edition.
Why This Matters for Canadian Organizations
On-premises Exchange remains common across Canadian municipal governments, school boards, healthcare networks, and mid-market enterprises still running local mail infrastructure alongside or instead of Exchange Online, often due to data residency preferences or legacy application dependencies. A successful exploit hands an attacker read access to email, attachments, and calendar data across an entire mailbox, a foothold regularly preceding business email compromise and wire fraud schemes targeting Canadian finance and procurement teams. Under OSFI B-13, federally regulated institutions running on-premises Exchange carry a direct obligation to patch known critical vulnerabilities on a defined timeline, and any resulting exposure of personal data triggers PIPEDA breach notification requirements regardless of sector.
What to Do
Exchange administrators should apply Microsoft’s August security update immediately if it has not already been deployed, then confirm Extended Protection for Authentication is enabled across all Exchange roles rather than assuming the patch alone closes the gap. Organizations unable to patch right away should restrict MRSProxy and related endpoints from direct internet exposure through a reverse proxy or VPN requirement, and review mailbox access logs for anomalous MAPI or EWS activity consistent with credential relay. Security teams should check exposure using the Netherlands NCSC’s published indicators, detailed by BleepingComputer.






