Hundreds of Obsolete, At-Risk Exchange Servers Remain Throughout Australia
We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!
Main Highlights
- As of August 31, 382 Exchange servers in Australia and 56 in New Zealand remain exposed to CVE-2026-62911, three weeks post Microsoft’s resolution.
- Publicly accessible exploit code now exists, with NCSC-NL cautioning that an unauthenticated attacker might gain arbitrary code execution capabilities.
- ASD is advising entities still operating outdated Exchange versions to take action, or segment their networks if they cannot replace them.
Vulnerable Exchange Servers: An Increasing Issue
Unpatched and old Microsoft Exchange servers susceptible to a serious authentication bypass flaw are prevalent in Australian and New Zealand networks, endangering organizations’ mailboxes with potential total compromise. Compounding the issue, active exploit code is now available to the public for this vulnerability.
Scope of the Vulnerability
The ShadowsServer Foundation, a nonprofit focused on security monitoring, reported that as of August 31, there are 382 Exchange servers in Australia and 56 in New Zealand left vulnerable to CVE-2026-62911, three weeks after Microsoft provided a fix. The versions affected comprise older Exchange Server 2016, 2019, and Subscription Edition, which complicates the patching situation.
Extended Security Updates
Exchange 2016 and 2019 only receive security updates through Microsoft’s Extended Security Updates (ESU) program now. This indicates that organizations operating those versions are incurring costs for ongoing support on infrastructure they have yet to update or transition to cloud-hosted Exchange.
Exploitation Threats and Alerts
The National Cyber Security Centre of the Netherlands (NCSC-NL) announced on August 28 that exploit code proof-of-concept had surfaced online. NCSC-NL upgraded its alert and cautioned that an unauthenticated attacker might execute arbitrary code.
Microsoft’s Position
Microsoft has yet to validate active exploitation occurring in real-world settings, and the vulnerability does not currently show up in the United States Cybersecurity and Infrastructure Agency’s Known Exploited Vulnerabilities (CISA-KEV) database. The flaw is rated with a CVSS 3.1 score of 8 out of 10, permitting an attacker to capture authentication traffic and replay it to obtain elevated privileges on an Exchange server.
Recommendations from Authorities
The flaw was identified by Orange Tsai from the DEVCORE Research Team during the Pwn2Own Berlin 2026 competition. When queried regarding the vulnerability by TechBest, the Australian Signals Directorate (ASD) urged organizations still using legacy Exchange to respond promptly.
ASD’s Suggestions
“Outdated technology lacking critical security updates and patches is an appealing target for cybercriminals and is more susceptible to attacks,” stated an ASD representative. The directorate further recommended that if legacy systems cannot be updated, organizations should segment their networks to safeguard their most vital systems, according to ASD.
Worldwide Context
ASD continues to provide ongoing guidance on Exchange Server security hardening and end-of-support strategies. On a global scale, as of August 31, 2026, ShadowServer reported 21,899 vulnerable Exchange servers, indicating that slow patching and upgrading is not solely an issue localized to the Oceania region.
Conclusion
Outdated Microsoft Exchange servers throughout Australia and New Zealand still exhibit vulnerability to security threats, despite a fix being offered by Microsoft. The ongoing existence of these servers creates significant security challenges, leading authorities like ASD to issue urgent recommendations for organizations to either upgrade or secure their infrastructures.




















