The 90-second version for a busy owner: If your email still runs on a Microsoft Exchange Server your company or an IT provider operates, whether on-premises or hosted for you on an MSP, Azure, or colocation server, rather than only Microsoft 365, and that server is Exchange 2016, 2019, or Subscription Edition, you need someone to confirm this week that it has the August 2026 security update installed. A flaw tracked as CVE-2026-62911 lets an attacker impersonate the Exchange server itself, and as of early September nearly 22,000 on-premises Exchange servers worldwide were still unpatched and reachable from the internet, roughly 6,200 of them in the United States, per Help Net Security. Working exploit code is now circulating publicly, which is what turned a footnote in August's patch release into a September scramble, per BleepingComputer.
Key takeaway: Microsoft shipped the fix on August 11, 2026. There is no Exchange Emergency Mitigation stopgap for this one, so the August update is the only fix and it takes priority over everything else, per FrankysWeb. If nobody at your company can tell you whether that update is on your server, treat that uncertainty as a "no" until proven otherwise.
Not sure whether your email runs on an in-house Exchange server at all, or who is responsible for patching it? Preferred Data Corporation has kept North Carolina businesses patched, migrated, and defended since 1987, from its home base in High Point and across the Piedmont Triad. Call (336) 886-3282 or request an email-server exposure check.
Why is a bug patched in August suddenly an emergency in September?
Because the exploit went public. When Microsoft disclosed CVE-2026-62911 on the August 11 Patch Tuesday, it carried a CVSS severity of 8.0 and an initial assessment that exploitation was less likely, per Microsoft's advisory. That assessment held until researchers released working proof-of-concept code, at which point "less likely" became "anyone who can download a script." The Netherlands' national cyber agency, NCSC-NL, flagged that a working exploit is now circulating online, per Help Net Security.
The gap between disclosure and public exploit is the danger window, and a lot of North Carolina shops slept through it. The flaw was found by Orange Tsai of the DEVCORE research team working with Trend Micro's Zero Day Initiative, per Help Net Security; the three-bug chain earned a $200,000 prize at Pwn2Own Berlin 2026, per Forkast. What wins a hacking contest becomes a copy-paste script fast, and this one already has. The 22,000 servers still exposed in early September are not exposed because the patch is hard to install. They are exposed because nobody was watching, per BleepingComputer.
What does CVE-2026-62911 actually do to an Exchange server?
It lets an attacker trick your Exchange server into treating the attacker as itself, and take over mailboxes from there. The next paragraph is for whoever actually administers the box; if that is not you, skip to what the takeover means. Exchange exposes an endpoint called MRSProxy, used for moving mailboxes, that accepts Negotiate authentication but fails to check channel bindings, the control that enforces Extended Protection for Authentication. Without that check, an attacker can relay the authentication of the Exchange server's own machine account to the endpoint and is then treated as that account, per FrankysWeb.
Microsoft classifies the result as an authentication-bypass privilege escalation rated 8.0, per Microsoft. Security researchers went further and chained the relay into SYSTEM-level remote code execution, per Forkast. The plain-English translation for a plant manager: an attacker who can reach your Exchange server over the internet can end up running commands as a highly privileged account, which on most small networks is a running start at your file server, your user directory, and everything else that trusts the mail system.
Quotable definition: An NTLM relay attack is when an attacker captures your system authenticating to one service and forwards that authentication to a second service that never verified who was really on the other end. CVE-2026-62911 works because Exchange's mailbox-move endpoint accepted a relayed login it should have rejected.
One detail matters more than any other for the decision this forces: the flaw affects the on-premises Exchange Server product only (versions 2016, 2019, and Subscription Edition), wherever that server runs. Exchange Online, the version that lives inside Microsoft 365, is not affected, per Help Net Security. A business with no on-premises Exchange server at all already sat this one out. The trap is hybrid: if you moved mailboxes to Microsoft 365 but kept an on-prem Exchange server for recipient management, mail relay, or migrations, that server still exposes the flaw and still needs the August update.
Is my email one of the exposed servers?
Two questions decide whether you must patch, a third decides how fast. First: do you run Microsoft Exchange Server, rather than only Microsoft 365 (Exchange Online), whether that server sits in your building or is hosted for you on an MSP, Azure, or colocation server? Second: is it Exchange 2016, 2019, or Subscription Edition? If both are yes, you need the August update regardless of exposure, because an attacker with any foothold inside your network, such as a compromised workstation or VPN account, can reach the endpoint. Third, for priority: can that server be reached from the public internet, which it usually can if staff get email on their phones without a VPN? If so, patch today rather than this week.
There is a second, quieter problem underneath the patch. Exchange Server 2016 and 2019 are already out of support and require paid Extended Security Updates to keep getting fixes at all, per Help Net Security. So a North Carolina shop running one of these servers is not only exposed to this specific flaw, it is running email on a platform Microsoft has stopped supporting in the normal way. In Germany, the national cyber agency BSI estimated that roughly 85% of on-premises Exchange servers in the country were still vulnerable to this flaw as of late August, per Help Net Security. There is no reason to think the Piedmont Triad is dramatically better.
| The situation | Patch and keep the on-prem server | Migrate to Microsoft 365 and retire the server |
|---|---|---|
| CVE-2026-62911 | Install the August update now, verify it | Not affected once the Exchange server is fully decommissioned; a hybrid server kept for management or relay still needs the update |
| Next Exchange zero-day | You are back on the treadmill | Microsoft patches the service for you |
| End of support | Already out of support, paying for ESU | Supported service, no ESU to buy |
| Attack surface | A privileged server facing the internet | No mail server for you to defend |
Want a straight answer on whether your Exchange box is patched, exposed, and worth keeping at all? Call Preferred Data Corporation at (336) 886-3282 or explore cloud and Microsoft 365 solutions.
The fix this week, and the bigger decision behind it
The immediate move is not complicated: install the August 2026 Exchange security update, then verify from the server itself that it actually applied, because a half-finished Exchange update that reports success is a classic trap. Do not go looking for an Emergency Mitigation Service rule to buy time, because there is not one for this flaw; the update is the fix and nothing else stands in for it, per FrankysWeb. Confirm Extended Protection for Authentication is enabled across your Exchange endpoints while you are in there, since the missing channel-binding check is exactly the relay weakness Extended Protection closes, per FrankysWeb. If you genuinely cannot patch this week, at minimum get the server off the public internet so a random scanner cannot reach the vulnerable endpoint.
Then have the harder conversation. This is at least the third on-premises Exchange fire drill many small shops have run in a single year, and each one costs somebody an evening and the owner a bad night's sleep, with the standing risk that the one skipped patch is the one that becomes a breach. For a 30-person distributor in Greensboro or a machine shop near Hickory, there is no strategic reason to run your own internet-facing mail server in 2026. The catch nobody mentions, and the real reason your last IT provider never moved you, is that your ERP order confirmations, your scan-to-email copier, and your warehouse label printer probably relay mail through that server, so a migration has to re-point every one of them or those messages quietly stop going out. That is planning work, not a blocker: scoped up front around mailbox sizes, bandwidth, and any legacy public folders, a move like this brings your archived mail across and keeps mailbox downtime to a minimum.
Ready to get off the Exchange patch treadmill for good? Preferred Data Corporation is at 1208 Eastchester Drive, Suite 131, High Point, NC 27265. Call (336) 886-3282 or start with a managed IT assessment.
The contrarian read from someone who patches these for a living
Everyone frames this as a patching failure, and it is, but that misses the real lesson. The reason 22,000 Exchange servers sat exposed for three weeks is not that patching is technically hard. It is that on-premises Exchange has quietly become an orphan on most small networks. The person who set it up left. The IT company that "handles email" assumed the client would call if something broke. Nobody owns the monthly job of reading Microsoft's advisory and confirming the update landed. An orphaned server does not patch itself, and Exchange is a big, privileged, internet-facing orphan.
Here is the unpopular part: for the vast majority of North Carolina small businesses, the right answer to "how do we secure our Exchange server" is "stop having one." Migrating to Microsoft 365 does not make you invulnerable, and anyone who tells you the cloud is automatically safe is selling something. What it does is hand the patching, the uptime, and the round-the-clock watching of the single most attacked server on your network to a vendor whose only job is defending it. That trade is worth making before the next zero-day, not during it. Pair the move with a real Microsoft 365 backup, because Microsoft protects the service, not your data from your own mistakes.
Straight answers on the CVE-2026-62911 scramble
Is CVE-2026-62911 being actively exploited? Not confirmed as of early September. A working proof-of-concept exploit is circulating publicly, flagged by the Netherlands' NCSC-NL, but no in-the-wild attacks had been reported yet and CISA still listed exploitation as none, per Forkast. With point-and-click exploit code public and roughly 22,000 servers exposed, the window before the first wave is already closing, per BleepingComputer.
We are a small shop. Are we really a target? Yes. Mass exploitation is indiscriminate: attackers scan the whole internet for the vulnerable endpoint and hit whatever answers, so a 30-person plant is as reachable as a Fortune 500. Size does not hide you when the exploit is automated and your server is one of roughly 22,000 that answer the scan.
Does this affect Microsoft 365 or Exchange Online? No, Exchange Online itself is not affected; the flaw affects the on-premises Exchange Server product only, wherever it runs (in your building, an MSP datacenter, an Azure VM, or a colo), per FrankysWeb. The exception is a hybrid setup: if you moved mailboxes to Microsoft 365 but still run an Exchange Server for recipient management or relay, that server is affected and needs the update.
What is the actual fix? Install the August 2026 Exchange security update. There is no Emergency Mitigation Service workaround for this flaw, so the update is the fix and takes priority, and you should also confirm Extended Protection for Authentication is enabled, per FrankysWeb.
We patched in August. Are we done? Verify it from the server, do not assume. Then check that Extended Protection is enabled and that the server is not needlessly exposed to the whole internet. A patched server on an unsupported platform is safer today and still on borrowed time.
Should a small NC business still run its own Exchange server? For most, no. Exchange 2016 and 2019 are out of support and need paid ESU, per Help Net Security, and each new zero-day restarts the same emergency. Migrating to Microsoft 365 removes the server you keep having to defend.
Related resources
- Cloud and Microsoft 365 solutions
- Managed IT services for North Carolina businesses
- Managed cybersecurity
- Data protection and backup
- Exchange Server 2016 and 2019 ESU ends October 2026: NC SMB email migration playbook
- Exchange Zero-Day CVE-2026-42897: NC SMB Action Plan
- Microsoft 365 SaaS backup: the shared-responsibility gap for NC SMBs
The Monday move is small and specific: find out, today, whether you run an on-premises Exchange server, whether the August update is on it, and whether it is reachable from the internet. If any of those answers is "I do not know," that is the finding. Preferred Data Corporation helps businesses across High Point and the Piedmont Triad answer those three questions and decide whether that server should exist at all. Call (336) 886-3282 or request an email-server exposure check.