Wire · technology
Microsoft Exchange Exploit Requires No Password: 22,000 Servers Exposed, ESU Ends October
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 3 September 2026 · Fusion42 review
A public, weaponized exploit targets a critical Microsoft Exchange vulnerability (CVE-2026-62911) that requires no credentials, exposing nearly 22,000 unpatched servers worldwide. The vulnerability bypasses authentication via a flawed HTTP.sys endpoint, with patching impossible for many running unsupported versions as Microsoft's Extended Security Update program ends in October 2026.
This Wire brief sits within Fusion42's coverage of Cybersecurity.
◆ ◆ The Wire takeaway
This vulnerability turns Microsoft Exchange servers into freely accessible targets, forcing security-focused founders to push emergency patches or rethink server exposure immediately. Unsupported versions lose protection permanently after October, signalling urgent risk for all relying on Exchange infrastructure.
◆ Coverage
1 source · 3 Sep 2026
◆ Related on Wire
◆ Topics