Exchange Server 2016 - SE | 85 Percent in Germany Unpatched ⏱ 3 min read

Exchange Server 2016 - SE | 85 Percent in Germany Unpatched

At the end of August, CERT-Bund published a figure summarizing the patch status of German mail infrastructure: Around 85 percent of on-premises Exchange servers in Germany are vulnerable to CVE-2026-62911.

Microsoft closed the vulnerability on August 11, 2026, as part of the August Patch Tuesday. Since August 14, the BSI has been informing German network operators about vulnerable systems in their networks.

Why the Vulnerability Is Critical

CVE-2026-62911 is an authentication bypass via capture-replay. Affected are Exchange Server 2016, Exchange Server 2019, and the Subscription Edition. Exchange Online is not affected. The attack targets the MRSProxy endpoint, which is used to move Exchange mailboxes between servers and in hybrid environments.

In isolation, the vulnerability is a privilege escalation that requires an already authenticated context. This is the source of the apparent contradiction in reports. Orange Tsai from the DEVCORE research team demonstrated it at Pwn2Own Berlin 2026 as part of a chain of three vulnerabilities that together enable code execution with SYSTEM privileges. A coercion technique forces authentication, after which the replay is triggered. This turns the privilege escalation into an attack without prior login. If successful, the attacker gains control over all user mailboxes, according to Microsoft: reading emails, sending emails, downloading attachments.

The proof of concept has been public since the end of August. No confirmed attacks in the wild have been reported so far, though this is not a reliable state given the published exploit code.

Why the Number Is So High

The 85 percent may appear to be negligence, but it is primarily a licensing issue. Regular support for Exchange 2016 and 2019 ended in October 2025. Security updates have since only been available through the paid Extended Security Updates program, which expires in October 2026.

The BSI is aware of only nine servers in Germany running versions 2016 and 2019 with ESU patches installed. As of the end of October 2025, 92 percent of approximately 33,000 German on-premises servers were running unsupported versions.

Those who haven't patched here often don't have a patch available but rather an open migration task. On August 31, Shadowserver counted 21,899 unpatched systems worldwide that are accessible from the internet, including 5,100 in Germany and 6,200 in the USA.

Is my server vulnerable?

The dividing line is the August 2026 security update. Anything below that is vulnerable, regardless of which Cumulative Update is installed. These versions close the gap:

VersionBuild
Exchange Server SE RTM15.2.2562.46
Exchange Server 2019 CU1515.2.1748.49
Exchange Server 2019 CU1415.2.1544.44
Exchange Server 2016 CU2315.1.2507.72

Check the installed version in the Exchange Management Shell:

Get-Command Exsetup.exe | ForEach-Object {$_.FileVersionInfo}

Compare the displayed build number with the version line. If it is lower, the August update is missing, and your server's MRSProxy endpoint is exposed.

What to do now

For the Subscription Edition, the security update KB5121573 is available, which the BSI considers the direct solution to the vulnerability. For 2016 and 2019, two options remain: active participation in ESU or restricting internet access until the server is replaced.

First, verify whether OWA, ECP, Autodiscover, and MRSProxy need to be accessible without filtering.

Conclusion

A published exploit combined with 85 percent of systems unpatched creates a window that, based on experience, will close in days, not weeks. For Exchange SE, this is a maintenance task. For 2016 and 2019, it’s the trigger to finally schedule a replacement, as the last affordable patch option ends in October 2026.

Read more: M365 Defender for Endpoint: Difference Between Antivirus and EDR explains why, after a relay attack, you need to see process chains on the server and not just file detections, and M365 Exchange Online: EWS Deadline Approaching! outlines which legacy protocols will be phased out in the cloud simultaneously.


Share:
Noch keine Kommentare

Sei der Erste und starte die Diskussion mit einem hilfreichen Beitrag.

Leave a comment

Dein Beitrag wird vor der Veröffentlichung kurz geprüft — fachlich, respektvoll und auf den Punkt ist hier genau richtig.

E-Mail Adresse wird nicht veröffentlicht.