Nearly 22,000 Microsoft Exchange servers remain exposed to CVE-2026-62911, a high-severity authentication bypass that lets attackers hijack user mailboxes. Patches have been available since August 2026. This vulnerability affects Exchange Server 2016, 2019, and Subscription Edition.
This checklist addresses the organizational failures creating this exposure. It's designed for security teams managing on-premises Exchange infrastructure or evaluating whether you should still be running it.
What This Checklist Covers
This audit targets three failure modes: patch deployment breakdowns, legacy system dependencies, and the decision framework for system retirement. Each item requires a yes/no answer. If you can't answer "yes" with documentation, you're exposed.
The checklist applies whether you're managing Exchange directly or through a managed service provider. If you own the risk, you own the audit.
Prerequisites
Before you start, gather:
- Current inventory of all Exchange servers (on-premises and hybrid)
- Patch management logs for the past 90 days
- Extended Security Update (ESU) enrollment status for Exchange 2016/2019 instances
- Change management approval records for Exchange patches
- Migration project plans (if any exist)
- Service level agreements with any third-party Exchange administrators
You'll need access to vulnerability scanning results and your asset management database. If you don't have either, that's your first finding.
Checklist Items
1. Do you have a complete inventory of all Exchange servers in your environment, including version numbers and patch levels?
Reference: NIST SP 800-53 CM-8 (Information System Component Inventory)
Good looks like: A machine-readable asset database updated within 24 hours of any configuration change, queryable by version and patch date, with ownership assigned to specific teams.
2. Have you applied all available security updates to Exchange servers within 14 days of release?
Reference: CISA Binding Operational Directive 22-01 (Reducing the Significant Risk of Known Exploited Vulnerabilities)
Good looks like: Automated patch deployment to test environments within 72 hours, production deployment within 14 days, with documented exceptions requiring executive approval and compensating controls.
3. If you're running Exchange 2016 or 2019, are you enrolled in the Extended Security Updates Program and receiving patches?
Reference: Microsoft Exchange Server support lifecycle policy
Good looks like: Active ESU subscription with proof of payment, confirmed patch delivery to all covered systems, and a documented end date for the ESU program (October 2026) with migration plans initiated.
4. Are all Exchange servers accessible only from internal networks, with no direct internet exposure?
Reference: CIS Controls v8.1 (Establish and Maintain a Secure Network Architecture)
Good looks like: Network segmentation enforced at the firewall level, Outlook Web Access published through a reverse proxy or application delivery controller, and external vulnerability scans confirming no direct Exchange fingerprints visible from the internet.
5. Do you have documented business justification for continuing to operate on-premises Exchange instead of migrating to Exchange Online?
Reference: Risk Management Framework decision documentation requirement
Good looks like: A written analysis comparing Total Cost of Ownership, Total Cost of Risk, regulatory constraints, and technical dependencies, reviewed within the past 12 months, with executive sign-off acknowledging the security implications of remaining on-premises.
6. Have you tested your ability to restore Exchange from backup within your Recovery Time Objective?
Reference: ISO 22301 (Business Continuity Management)
Good looks like: Quarterly restore tests to isolated environments, documented restore times under four hours for critical mailbox databases, and verified integrity of restored data including mailbox permissions and calendar items.
7. Do you monitor Exchange authentication logs for replay attack patterns?
Reference: NIST SP 800-61 Rev. 2 (Computer Security Incident Handling Guide)
Good looks like: SIEM correlation rules detecting duplicate authentication tokens, alerting on privilege escalation attempts within mailbox contexts, and automated blocking of suspicious sessions with security team notification.
8. Have you conducted a tabletop exercise simulating a mass mailbox compromise scenario?
Reference: NIST Cybersecurity Framework (CSF) 2.0, Respond function
Good looks like: Annual exercises involving IT, legal, communications, and executive leadership, with documented playbooks for user notification, forensic mailbox preservation, and regulatory disclosure requirements under SEC Cybersecurity Disclosure rules if applicable.
9. If you cannot patch immediately, have you implemented compensating controls and documented them formally?
Reference: PCI DSS Requirement 6.1 (Compensating Controls Worksheet)
Good looks like: Written compensating control analysis describing the vulnerability, why patching is delayed, what controls reduce risk (network isolation, enhanced monitoring, MFA enforcement), and a remediation deadline within 30 days.
10. Do you have a funded migration plan with executive approval to exit on-premises Exchange before October 2026?
Reference: Risk treatment planning under ISO/IEC 27005
Good looks like: A project charter with budget allocation, assigned project manager, defined migration waves by business unit, and board-level acknowledgment that Extended Security Updates end in October 2026, creating unacceptable risk beyond that date.
Common Mistakes
Treating ESU as a long-term strategy. Extended Security Updates for Exchange 2016 and 2019 end in October 2026. Organizations treating ESU as indefinite support are creating a cliff-edge risk event. If you're on ESU now, you should be 60% through your migration project.
Assuming internal-only systems don't need immediate patching. CVE-2026-62911 requires an attacker to already have basic privileges on the server. If you're relying on "it's internal" as your control, you're assuming no insider threat, no compromised credentials, and no lateral movement from other breached systems. That assumption fails regularly.
Patching without testing the patch process itself. The existence of 21,899 unpatched servers suggests patch deployment failures, not just policy failures. If your patch management system can't reliably deploy Exchange updates, you need to fix the deployment mechanism before the next critical vulnerability drops.
Conflating "no known exploitation" with "low risk." Exploit code for CVE-2026-62911 is publicly available. The Netherlands National Cyber Security Centre confirmed this. The gap between "exploit published" and "exploit used" is measured in days, not months.
Deferring the migration decision. Around 85% of on-premises Exchange servers in Germany remain vulnerable to this flaw. This isn't a patching problem at scale; it's an architecture problem. Organizations still debating whether to migrate are burning time they don't have.
Next Steps
If you answered "no" to items 1-4, you have an operational control failure requiring immediate remediation. Brief your executive leadership today.
If you answered "no" to items 5 or 10, you have a strategic planning gap. On-premises Exchange without a funded exit plan is an unmanaged risk position.
If you answered "no" to items 6-9, you have incident readiness and resilience gaps. A mailbox compromise affecting all users will generate legal, regulatory, and operational consequences your current controls can't contain.
Schedule a 30-day follow-up audit. Patch velocity and migration progress are the only metrics that matter. Everything else is commentary on a system you shouldn't be running.



