How to secure Exchange Server beyond the CVE-2026-62911 fix

Remote access has always been a core part of how on-premises Exchange works. Users need OWA to read their email from outside the office. Their devices need Autodiscover to set themselves up automatically. Keeping both reachable means keeping Exchange accessible from the Internet, and that opens up more of the server than most organisations realise.
CVE-2026-62911 is the latest example. Microsoft released the fix on August 11, 2026. Three weeks later, The Shadowserver Foundation identified nearly 22,000 Internet-facing Exchange servers that were still unpatched, including roughly 6,200 in the United States and 5,100 in Germany.
That leaves organizations with two problems to solve: how quickly they can close the vulnerability, and how much exposure remains while they do it.
Endpoint Central addresses both. Secure Private Access takes Exchange off the open Internet, so only your authenticated users on managed devices can reach it. Patch management then closes the vulnerability itself, deploying the fix automatically across every managed server within hours of release.
A CVSS 8.0 that can expose every mailbox
Microsoft classifies this CVE as an 'authentication bypass by capture-replay in Microsoft Exchange Server,' rated CVSS 8.0 (High). Security researcher Orange Tsai of the DEVCORE Research Team discovered it and demonstrated it at Pwn2Own Berlin 2026, earning the maximum $200,000 award at the competition.
Per Microsoft's advisory, a successful attacker can 'take over the mailboxes of all Exchange users': reading email, sending email, and downloading attachments.
Affected versions:
Exchange Server 2016 (Cumulative Update 23)
Exchange Server 2019 (Cumulative Update 14 and 15)
Exchange Server Subscription Edition (SE) RTM
How the attack works
The vulnerability is in MRSProxy, an endpoint Exchange uses for mailbox migrations. In unpatched versions, an attacker can intercept an authentication token from one Exchange server and present it to another, which accepts it as valid. From there, they can write a web shell to the server and run commands as SYSTEM, giving them full control.
The August 2026 patch closes this by tying each authentication token to the specific session it came from. A token from a different session is rejected.
The Zero Day Initiative put it plainly in their August 2026 review: 'This bug was one of the ones demonstrated at Pwn2Own Berlin, so ignore Microsoft's exploitability and Exploit Code Maturity ratings. We handed them working exploits, so this is a real threat.'
Exchange 2016 and 2019: Support Ends in October 2026
Microsoft released update KB5121573 (SU9) for Exchange Server SE on August 11, 2026; details at the Exchange team's August 2026 Security Update blog. Exchange 2016 and 2019 are out of mainstream support; only organizations in Microsoft's Period 2 Extended Security Update program receive this fix, and that program closes in October 2026.
The exposure behind the CVE
Here is the part that rarely gets talked about.
MRSProxy is a migration tool. Most remote users have no reason to reach it, yet on 21,899 servers it was in the same published directory as OWA, Autodiscover, and ActiveSync, reachable from any IP. When you publish an entire server rather than specific applications, you cannot control what the Internet can reach. The patch closes this hole. The server stays Internet-facing, and the next CVE starts its clock.
What actually changes the risk posture is two things together: reducing what the Internet can reach in the first place, and applying patches faster once that boundary is in place. Endpoint Central addresses both.
Secure Private Access: Keep Exchange off the public Internet
Secure Private Access is a Zero Trust Network Access (ZTNA) capability built into Endpoint Central, and a more secure alternative to VPN. Instead of Exchange being reachable by anyone on the Internet, only your authenticated users on managed, trusted devices can reach it.
A flaw on a server the Internet cannot reach is effectively invisible to attackers. Your team patches it on their own schedule, not because someone is already at the door. Endpoint Central's patch management handles that part, deploying the August 2026 Exchange update automatically across every managed server so the window between patch release and deployment closes in hours rather than weeks.
For your users, nothing changes. Outlook, OWA, and ActiveSync on their phones all continue working exactly as before. For your administrators, Exchange Control Panel, RDP, and remote PowerShell are no longer Internet-facing. MRSProxy, the endpoint at the center of CVE-2026-62911, has no reason to be Internet-reachable for non-hybrid organisations. Under this model, it is not.
Start here, then work outward
Start with Secure Private Access. Your administrator tools should never have been Internet-facing, and that is the right place to begin. Extend to your remote users once that is stable, and apply the August 2026 patch across your managed servers.
Patching closes the vulnerability you know about. Secure Private Access reduces the risk from the ones you do not know about yet.