< Back to all clusters
[TECHNOLOGY] · Germany · 5 sources

started · updated

Microsoft Exchange: 85% of German servers remain unpatched and vulnerable

The German Federal Office for Information Security (BSI) has issued a warning regarding a critical security vulnerability, CVE-2026-62911, affecting Microsoft Exchange environments. Approximately 85 percent of on-premises Exchange servers operating in Germany remain unpatched and vulnerable to attack, despite security updates being available since August.

This vulnerability is particularly prevalent in widely used Exchange 2016 and 2019 versions. The BSI noted a significant deficit in infrastructure security, highlighting that only nine servers nationwide have implemented the necessary Extended Security Updates (ESU) to close the specific flaw. Such delays in patching pose a substantial risk to business continuity for organizations relying on these architectures for internal communication.

In a related context, Microsoft executive Igor Sakhnov warned that the window for defending against vulnerabilities is shrinking drastically. While defenders traditionally had days or weeks to respond to disclosures, attackers can now exploit flaws within hours. Sakhnov noted that while AI can accelerate patching, it also enables attackers to move faster, suggesting that organizations should supplement traditional patching with rapid network-based controls to reduce their attack surface.

Entities

Federal Office for Information Security · Igor Sakhnov · Microsoft