$ techbeacon▋
CVE & Exploits

Thousands of Exchange Servers Remain Unpatched, Leaving Mailboxes Open to Hijack

Thousands of Exchange Servers Remain Unpatched, Leaving Mailboxes Open to Hijack

Security researchers have identified close to 22,000 Microsoft Exchange servers that are still exposed to a high‑severity authentication bypass flaw, a condition that could let threat actors take control of any user mailbox hosted on the affected systems.

The vulnerability, which bypasses normal credential checks, enables an attacker to impersonate any user and read, modify, or delete email content. Because Exchange servers are often the hub of corporate communication, the potential impact ranges from credential harvesting to the deployment of ransomware or other malicious payloads.

Microsoft issued patches for the flaw in early 2021, and the updates are available through standard Windows Update channels and the Exchange Management console. Despite the availability of fixes, a sizable segment of organizations—particularly small and mid‑size firms—have not applied the patches, leaving their mail infrastructure vulnerable.

Experts warn that unpatched servers can serve as a foothold for broader network compromise. Once an attacker gains mailbox access, they can exfiltrate sensitive data, forge trusted communications, or pivot to other internal resources, escalating the risk of large‑scale data breaches.

The latest count comes from a scan conducted by BleepingComputer, which routinely monitors the internet for exposed services. Their findings highlight a continued gap between the release of security updates and the implementation of those patches in real‑world environments.

Authorities and cybersecurity advisories are urging administrators to verify that all Exchange installations are running the latest code, to enable multi‑factor authentication where possible, and to monitor logs for suspicious mailbox activity. Ongoing monitoring and rapid remediation are seen as essential steps to prevent exploitation before attackers can capitalize on the remaining vulnerable servers.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related