Hundreds of Obsolete, At-Risk Exchange Servers Remain Throughout Australia


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Main Highlights

  • As of August 31, 382 Exchange servers in Australia and 56 in New Zealand remain exposed to CVE-2026-62911, three weeks post Microsoft’s resolution.
  • Publicly accessible exploit code now exists, with NCSC-NL cautioning that an unauthenticated attacker might gain arbitrary code execution capabilities.
  • ASD is advising entities still operating outdated Exchange versions to take action, or segment their networks if they cannot replace them.

Vulnerable Exchange Servers: An Increasing Issue

Unpatched and old Microsoft Exchange servers susceptible to a serious authentication bypass flaw are prevalent in Australian and New Zealand networks, endangering organizations’ mailboxes with potential total compromise. Compounding the issue, active exploit code is now available to the public for this vulnerability.

Scope of the Vulnerability

The ShadowsServer Foundation, a nonprofit focused on security monitoring, reported that as of August 31, there are 382 Exchange servers in Australia and 56 in New Zealand left vulnerable to CVE-2026-62911, three weeks after Microsoft provided a fix. The versions affected comprise older Exchange Server 2016, 2019, and Subscription Edition, which complicates the patching situation.

Extended Security Updates

Exchange 2016 and 2019 only receive security updates through Microsoft’s Extended Security Updates (ESU) program now. This indicates that organizations operating those versions are incurring costs for ongoing support on infrastructure they have yet to update or transition to cloud-hosted Exchange.

Exploitation Threats and Alerts

The National Cyber Security Centre of the Netherlands (NCSC-NL) announced on August 28 that exploit code proof-of-concept had surfaced online. NCSC-NL upgraded its alert and cautioned that an unauthenticated attacker might execute arbitrary code.

Microsoft’s Position

Microsoft has yet to validate active exploitation occurring in real-world settings, and the vulnerability does not currently show up in the United States Cybersecurity and Infrastructure Agency’s Known Exploited Vulnerabilities (CISA-KEV) database. The flaw is rated with a CVSS 3.1 score of 8 out of 10, permitting an attacker to capture authentication traffic and replay it to obtain elevated privileges on an Exchange server.

Recommendations from Authorities

The flaw was identified by Orange Tsai from the DEVCORE Research Team during the Pwn2Own Berlin 2026 competition. When queried regarding the vulnerability by TechBest, the Australian Signals Directorate (ASD) urged organizations still using legacy Exchange to respond promptly.

ASD’s Suggestions

“Outdated technology lacking critical security updates and patches is an appealing target for cybercriminals and is more susceptible to attacks,” stated an ASD representative. The directorate further recommended that if legacy systems cannot be updated, organizations should segment their networks to safeguard their most vital systems, according to ASD.

Worldwide Context

ASD continues to provide ongoing guidance on Exchange Server security hardening and end-of-support strategies. On a global scale, as of August 31, 2026, ShadowServer reported 21,899 vulnerable Exchange servers, indicating that slow patching and upgrading is not solely an issue localized to the Oceania region.

Conclusion

Outdated Microsoft Exchange servers throughout Australia and New Zealand still exhibit vulnerability to security threats, despite a fix being offered by Microsoft. The ongoing existence of these servers creates significant security challenges, leading authorities like ASD to issue urgent recommendations for organizations to either upgrade or secure their infrastructures.

Reader questions

Frequently asked questions

Fast answers to the questions readers ask most about Hundreds of Obsolete, At-Risk Exchange Servers Remain Throughout Australia.

What is the issue affecting Exchange servers?

The issue is a severe authentication bypass vulnerability termed CVE-2026-62911, enabling unauthenticated attackers to potentially execute arbitrary code on the compromised servers.

How many servers are impacted in Australia and New Zealand?

As of August 31, 382 servers are vulnerable in Australia, and 56 in New Zealand.

Which Exchange versions are affected?

The versions at risk include Exchange Server 2016, 2019, and Subscription Edition.

What measures should organizations with vulnerable servers take?

Organizations should either update or replace these servers or, if unable, segment their networks to safeguard critical systems.

Has Microsoft acknowledged active exploitation of this vulnerability?

Currently, Microsoft has not verified any active exploitation in real-world scenarios.

What is the position of the Australian Signals Directorate (ASD)?

ASD encourages organizations to promptly address the vulnerability and recommends network segmentation if upgrading is not an option.

Posted by Matthew Miller

Matthew Miller is a Brisbane-based Consumer Technology Editor at Techbest covering breaking Australia tech news.

Leave a Reply

Your email address will not be published. Required fields are marked *