









Zscaler Blog
Get the latest Zscaler blog updates in your inbox
Microsoft's August 2026 Patch Tuesday
included a fixfor CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The severity has a CVSS score of 8.0 from Microsoft.
As of September 1, threat intelligence group Shadowserver has identified around 22,000 Exchange servers that remain unpatched and exposed to the internet, including roughly 6,200 in the United States and 5,100 in Germany alone.
According to Microsoft, successful exploitation allows an attacker with basic privileges to take over all mailboxes on the targeted server, including reading and sending email and downloading attachments. The Netherlands National Cyber Security Centre (NCSC-NL) has confirmed that working exploit code is already publicly available.
If you're running an on-premises Exchange server, this post outlines practical steps you can take now, and a longer-term architectural approach worth considering.
The August 2026 Patch Tuesday update addresses CVE-2026-62911 directly. If you haven't applied it yet, that's the first priority.
A few important notes for older versions:
Patching is essential, but it's worth understanding why private application servers such as Exchange are repeatedly in this position. On-premises Exchange runs as an internet-facing service by design. Outlook Web App (OWA) needs to be accessible to users, which typically means it's reachable from the public internet. That reachability is what makes each new CVE a high-stakes race between patching and exploitation.
The NCSC-NL guidance to ensure Exchange is "accessible only internally" points at the right solution, but doesn't prescribe how to get there for organizations that still need to support remote access.
At the time of writing, CISA has not reported exploitations in the wild as of yet. But there's a meaningful shift in the threat landscape that makes this type of exposure a more pressing issue than it once was.
Earlier AI models gave attackers tools to automate reconnaissance. Today's frontier models, such as Anthropic's Mythos, represent a step change beyond that. They can identify a known vulnerability, develop a working exploit, and execute an attack in minutes, not days.
The practical implication: the window between a CVE being disclosed and exploitation at scale has compressed significantly. Our ThreatLabz 2026 Frontier AI Readiness Report showcased how the mean-time-to-exploit has actually gone negative – with attackers finding and exploiting vulnerabilities before they’re even disclosed. With CVE-2026-62911, exploit code is already public. An organization's ability to outpace exploitation through patching alone is less reliable than it used to be, particularly for internet-exposed infrastructure.
Zscaler Private Access (ZPA) allows organizations to eliminate the exposure of all private apps to internet-based attacks. This includes services like Exchange, which remain fully accessible to your users while being completely invisible to the internet. The way it works:

The fundamental difference from a traditional VPN is how and when access is granted. A VPN establishes a persistent, always-on network tunnel — once connected, a user has broad network-level access regardless of what they're actually doing. ZPA works differently: rather than maintaining a standing tunnel, it brokers short-lived, application-specific connections on demand, and only after identity and policy checks pass. Each session is purpose-built for a specific application, time-bound by policy, and torn down once the session ends — there's no residual network foothold. A VPN gateway or concentrator is itself exposed to the internet and a frequent attacker target; ZPA has no equivalent surface, because there's nothing listening for inbound connections to begin with.
If your Exchange server is behind ZPA, CVE-2026-62911 is effectively not exploitable from the internet, regardless of whether you've patched, because the authentication bypass requires reaching port 443 on the Exchange server in the first place.
If you have reason to believe a server may have been compromised before patching, additional controls are worth considering:
On-premises Exchange has been one of the most consistently targeted enterprise applications over the past several years. CISA has added 20 Exchange Server vulnerabilities to its Known Exploited Vulnerabilities catalog since November 2021; 14 of those have been linked to ransomware. With Exchange 2016 and 2019 losing security update support in October 2026, the risk profile for organizations still running those versions is only going to grow.
Whether an organization utilizes on-premise solutions like Exchange or SaaS environments like Microsoft 365, private applications will always remain a baseline necessity for maintaining data confidentiality, restricted access, and regulatory compliance.
For organizations evaluating their options, migration to Microsoft 365 removes the on-premises attack surface entirely. It's not the right move for everyone on every timeline, but it's worth including in the planning conversation while investing in architectures that would empower them to respond to vulnerabilities in real-time.
Priority | Action |
Immediate | Apply the August 2026 Patch Tuesday update |
Immediate | If patching is delayed, ensure Exchange is not internet-accessible |
Near-term | Deploy ZPA to broker all OWA access (managed and unmanaged devices) |
Near-term | Enable outbound inspection on Exchange traffic |
Consider | Deploy Workload Segmentation to contain potential lateral movement |
Consider | Deploy Deception to contain potential lateral movement |
Consider | Deploy AppShield to virtually patch exploits |
Strategic | Evaluate Microsoft 365 migration, especially if running Exchange 2016/2019 |
To learn more about how Zscaler can help you reduce exposure and prevent exploitation by frontier AI models, watch our on-demand webinar.
Thank you for reading
Disclaimer: This blog post has been created by Zscaler for informational purposes only and is provided "as is" without any guarantees of accuracy, completeness or reliability. Zscaler assumes no responsibility for any errors or omissions or for any actions taken based on the information provided. Any third-party websites or resources linked in this blog post are provided for convenience only, and Zscaler is not responsible for their content or practices. All content is subject to change without notice. By accessing this blog, you agree to these terms and acknowledge your sole responsibility to verify and use the information as appropriate for your needs.

Securing Data in the AI Era: Insights from the ThreatLabz 2025 Data@Risk Report

Can AI Detect and Mitigate Zero Day Vulnerabilities?

What to Look for in a Deception Technology Solution
![]()
By submitting the form, you are agreeing to our privacy policy.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。