Microsoft’s August 2026 Patch Tuesday included a fix for CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The severity has a CVSS score of 8.0 from Microsoft. As of September 1, threat intelligence group Shadowserver has identified around 22,000 Exchange servers that remain unpatched and exposed to the internet, including roughly 6,200 in the United States and 5,100 in Germany alone. According to Microsoft, successful exploitation allows an attacker with basic privileges to take over all mailboxes on the targeted server, including reading and sending email and downloading attachments. The Netherlands National Cyber Security Centre (NCSC-NL) has confirmed that working exploit code is already publicly available.If you’re running an on-premises Exchange server, this post outlines practical steps you can take now, and a longer-term architectural approach worth considering.  First: Apply the PatchThe August 2026 Patch Tuesday update addresses CVE-2026-62911 directly. If you haven’t applied it yet, that’s the first priority.A few important notes for older versions:Exchange 2016 and 2019 are on the Extended Security Update (ESU) program, which ends in October 2026. If you’re on either version, confirm you’re enrolled in ESU and apply the update. After October, these versions will no longer receive security fixes.If patching isn’t immediately possible, NCSC-NL’s guidance is to ensure the Exchange server is not reachable from the open internet until the patch can be applied. The Structural Issue: Internet ExposurePatching is essential, but it’s worth understanding why private application servers such as Exchange are repeatedly in this position. On-premises Exchange runs as an internet-facing service by design. Outlook Web App (OWA) needs to be accessible to users, which typically means it’s reachable from the public internet. That reachability is what makes each new CVE a high-stakes race between patching and exploitation.The NCSC-NL guidance to ensure Exchange is “accessible only internally” points at the right solution, but doesn’t prescribe how to get there for organizations that still need to support remote access. Why This Matters More in 2026 Than It Did in Prior YearsAt the time of writing, CISA has not reported exploitations in the wild as of yet. But there’s a meaningful shift in the threat landscape that makes this type of exposure a more pressing issue than it once was.Earlier AI models gave attackers tools to automate reconnaissance. Today’s frontier models, such as Anthropic’s Mythos, represent a step change beyond that. They can identify a known vulnerability, develop a working exploit, and execute an attack in minutes, not days.The practical implication: the window between a CVE being disclosed and exploitation at scale has compressed significantly. Our ThreatLabz 2026 Frontier AI Readiness Report showcased how the mean-time-to-exploit has actually gone negative – with attackers finding and exploiting vulnerabilities before they’re even disclosed. With CVE-2026-62911, exploit code is already public. An organization’s ability to outpace exploitation through patching alone is less reliable than it used to be, particularly for internet-exposed infrastructure. A Zero Trust Approach: Don’t Expose Exchange to the InternetZscaler Private Access (ZPA) allows organizations to eliminate the exposure of all private apps to internet-based attacks. This includes services like Exchange, which remain fully accessible to your users while being completely invisible to the internet. The way it works:Managed devices: The Zscaler client routes OWA traffic through an encrypted ZPA tunnel to the Exchange server. There’s no inbound connection to the server from the internet, and nothing for an attacker to probe or target.Unmanaged devices: ZPA Clientless Access provides a secure, authenticated, browser-based path for users on personal or partner devices, without requiring a VPN or opening any inbound ports.The fundamental difference from a traditional VPN is how and when access is granted. A VPN establishes a persistent, always-on network tunnel — once connected, a user has broad network-level access regardless of what they’re actually doing. ZPA works differently: rather than maintaining a standing tunnel, it brokers short-lived, application-specific connections on demand, and only after identity and policy checks pass. Each session is purpose-built for a specific application, time-bound by policy, and torn down once the session ends — there’s no residual network foothold. A VPN gateway or concentrator is itself exposed to the internet and a frequent attacker target; ZPA has no equivalent surface, because there’s nothing listening for inbound connections to begin with.If your Exchange server is behind ZPA, CVE-2026-62911 is effectively not exploitable from the internet, regardless of whether you’ve patched, because the authentication bypass requires reaching port 443 on the Exchange server in the first place. For Servers That May Already Be CompromisedIf you have reason to believe a server may have been compromised before patching, additional controls are worth considering:Zscaler Data Security (DLP) can inspect outbound traffic from Exchange infrastructure, helping detect data exfiltration or other malicious activity that might indicate a server has been compromised.Zscaler Deception places honeypots throughout your environment that provide high-fidelity signals that an attack is underway. With their multi-path reasoning, frontier AI models are particularly likely to trip over these decoys.Zscaler Cloud Workload Segmentation limits lateral movement, preventing an attacker who has gained a foothold on an Exchange server from moving to other parts of your environment.Zscaler Private Access (ZPA) with AppShield acts as an inline, real-time protective wrapper around your private applications. Rather than relying on reactive infrastructure patching, AppShield continuously shields your applications from exploit attempts and stops lateral threat movement in real time. Longer-Term: The Case for Migrating to Microsoft 365On-premises Exchange has been one of the most consistently targeted enterprise applications over the past several years. CISA has added 20 Exchange Server vulnerabilities to its Known Exploited Vulnerabilities catalog since November 2021; 14 of those have been linked to ransomware. With Exchange 2016 and 2019 losing security update support in October 2026, the risk profile for organizations still running those versions is only going to grow.Whether an organization utilizes on-premise solutions like Exchange or SaaS environments like Microsoft 365, private applications will always remain a baseline necessity for maintaining data confidentiality, restricted access, and regulatory compliance.For organizations evaluating their options, migration to Microsoft 365 removes the on-premises attack surface entirely. It’s not the right move for everyone on every timeline, but it’s worth including in the planning conversation while investing in architectures that would empower them to respond to vulnerabilities in real-time.  PriorityActionImmediateApply the August 2026 Patch Tuesday updateImmediateIf patching is delayed, ensure Exchange is not internet-accessibleNear-termDeploy ZPA to broker all OWA access (managed and unmanaged devices)Near-termEnable outbound inspection on Exchange trafficConsiderDeploy Workload Segmentation to contain potential lateral movementConsiderDeploy Deception to contain potential lateral movementConsiderDeploy AppShield to virtually patch exploitsStrategicEvaluate Microsoft 365 migration, especially if running Exchange 2016/2019To learn more about how Zscaler can help you reduce exposure and prevent exploitation by frontier AI models, watch our on-demand webinar.   

​[#item_full_content] Microsoft’s August 2026 Patch Tuesday included a fix for CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The severity has a CVSS score of 8.0 from Microsoft. As of September 1, threat intelligence group Shadowserver has identified around 22,000 Exchange servers that remain unpatched and exposed to the internet, including roughly 6,200 in the United States and 5,100 in Germany alone. According to Microsoft, successful exploitation allows an attacker with basic privileges to take over all mailboxes on the targeted server, including reading and sending email and downloading attachments. The Netherlands National Cyber Security Centre (NCSC-NL) has confirmed that working exploit code is already publicly available.If you’re running an on-premises Exchange server, this post outlines practical steps you can take now, and a longer-term architectural approach worth considering.  First: Apply the PatchThe August 2026 Patch Tuesday update addresses CVE-2026-62911 directly. If you haven’t applied it yet, that’s the first priority.A few important notes for older versions:Exchange 2016 and 2019 are on the Extended Security Update (ESU) program, which ends in October 2026. If you’re on either version, confirm you’re enrolled in ESU and apply the update. After October, these versions will no longer receive security fixes.If patching isn’t immediately possible, NCSC-NL’s guidance is to ensure the Exchange server is not reachable from the open internet until the patch can be applied. The Structural Issue: Internet ExposurePatching is essential, but it’s worth understanding why private application servers such as Exchange are repeatedly in this position. On-premises Exchange runs as an internet-facing service by design. Outlook Web App (OWA) needs to be accessible to users, which typically means it’s reachable from the public internet. That reachability is what makes each new CVE a high-stakes race between patching and exploitation.The NCSC-NL guidance to ensure Exchange is “accessible only internally” points at the right solution, but doesn’t prescribe how to get there for organizations that still need to support remote access. Why This Matters More in 2026 Than It Did in Prior YearsAt the time of writing, CISA has not reported exploitations in the wild as of yet. But there’s a meaningful shift in the threat landscape that makes this type of exposure a more pressing issue than it once was.Earlier AI models gave attackers tools to automate reconnaissance. Today’s frontier models, such as Anthropic’s Mythos, represent a step change beyond that. They can identify a known vulnerability, develop a working exploit, and execute an attack in minutes, not days.The practical implication: the window between a CVE being disclosed and exploitation at scale has compressed significantly. Our ThreatLabz 2026 Frontier AI Readiness Report showcased how the mean-time-to-exploit has actually gone negative – with attackers finding and exploiting vulnerabilities before they’re even disclosed. With CVE-2026-62911, exploit code is already public. An organization’s ability to outpace exploitation through patching alone is less reliable than it used to be, particularly for internet-exposed infrastructure. A Zero Trust Approach: Don’t Expose Exchange to the InternetZscaler Private Access (ZPA) allows organizations to eliminate the exposure of all private apps to internet-based attacks. This includes services like Exchange, which remain fully accessible to your users while being completely invisible to the internet. The way it works:Managed devices: The Zscaler client routes OWA traffic through an encrypted ZPA tunnel to the Exchange server. There’s no inbound connection to the server from the internet, and nothing for an attacker to probe or target.Unmanaged devices: ZPA Clientless Access provides a secure, authenticated, browser-based path for users on personal or partner devices, without requiring a VPN or opening any inbound ports.The fundamental difference from a traditional VPN is how and when access is granted. A VPN establishes a persistent, always-on network tunnel — once connected, a user has broad network-level access regardless of what they’re actually doing. ZPA works differently: rather than maintaining a standing tunnel, it brokers short-lived, application-specific connections on demand, and only after identity and policy checks pass. Each session is purpose-built for a specific application, time-bound by policy, and torn down once the session ends — there’s no residual network foothold. A VPN gateway or concentrator is itself exposed to the internet and a frequent attacker target; ZPA has no equivalent surface, because there’s nothing listening for inbound connections to begin with.If your Exchange server is behind ZPA, CVE-2026-62911 is effectively not exploitable from the internet, regardless of whether you’ve patched, because the authentication bypass requires reaching port 443 on the Exchange server in the first place. For Servers That May Already Be CompromisedIf you have reason to believe a server may have been compromised before patching, additional controls are worth considering:Zscaler Data Security (DLP) can inspect outbound traffic from Exchange infrastructure, helping detect data exfiltration or other malicious activity that might indicate a server has been compromised.Zscaler Deception places honeypots throughout your environment that provide high-fidelity signals that an attack is underway. With their multi-path reasoning, frontier AI models are particularly likely to trip over these decoys.Zscaler Cloud Workload Segmentation limits lateral movement, preventing an attacker who has gained a foothold on an Exchange server from moving to other parts of your environment.Zscaler Private Access (ZPA) with AppShield acts as an inline, real-time protective wrapper around your private applications. Rather than relying on reactive infrastructure patching, AppShield continuously shields your applications from exploit attempts and stops lateral threat movement in real time. Longer-Term: The Case for Migrating to Microsoft 365On-premises Exchange has been one of the most consistently targeted enterprise applications over the past several years. CISA has added 20 Exchange Server vulnerabilities to its Known Exploited Vulnerabilities catalog since November 2021; 14 of those have been linked to ransomware. With Exchange 2016 and 2019 losing security update support in October 2026, the risk profile for organizations still running those versions is only going to grow.Whether an organization utilizes on-premise solutions like Exchange or SaaS environments like Microsoft 365, private applications will always remain a baseline necessity for maintaining data confidentiality, restricted access, and regulatory compliance.For organizations evaluating their options, migration to Microsoft 365 removes the on-premises attack surface entirely. It’s not the right move for everyone on every timeline, but it’s worth including in the planning conversation while investing in architectures that would empower them to respond to vulnerabilities in real-time.  PriorityActionImmediateApply the August 2026 Patch Tuesday updateImmediateIf patching is delayed, ensure Exchange is not internet-accessibleNear-termDeploy ZPA to broker all OWA access (managed and unmanaged devices)Near-termEnable outbound inspection on Exchange trafficConsiderDeploy Workload Segmentation to contain potential lateral movementConsiderDeploy Deception to contain potential lateral movementConsiderDeploy AppShield to virtually patch exploitsStrategicEvaluate Microsoft 365 migration, especially if running Exchange 2016/2019To learn more about how Zscaler can help you reduce exposure and prevent exploitation by frontier AI models, watch our on-demand webinar.