← Back

Wire · technology

Microsoft Exchange Exploit Requires No Password: 22,000 Servers Exposed, ESU Ends October

Published

3 September 2026

Topic

technology

Sectors

Cybersecurity

Geography

Global

Source

Read at techtimes.com

Verified

Fusion42 · 3 September 2026 · Fusion42 review

A public, weaponized exploit targets a critical Microsoft Exchange vulnerability (CVE-2026-62911) that requires no credentials, exposing nearly 22,000 unpatched servers worldwide. The vulnerability bypasses authentication via a flawed HTTP.sys endpoint, with patching impossible for many running unsupported versions as Microsoft's Extended Security Update program ends in October 2026.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

This vulnerability turns Microsoft Exchange servers into freely accessible targets, forcing security-focused founders to push emergency patches or rethink server exposure immediately. Unsupported versions lose protection permanently after October, signalling urgent risk for all relying on Exchange infrastructure.

Coverage

1 source · 3 Sep 2026

Related on Wire

Topics

Cybersecuritymicrosoft-exchangezero-daysecurity-exploitextended-security-updatespatching-deadline