A vulnerability with the CVE ID CVE-2026-62911 and CVSS score of 9.8 allows access after compromise to other users' mailboxes, found in nearly 22,000 servers that had not received the fix for this issue. Microsoft's new requirements affect servers that dispatch mail to Exchange Online through an inbound connector of the OnPremises type, restricting and blocking messages from Exchange Server 2016 and 2019 unless the servers have been updated at least to the final public level of October 2025. This change is part of a broader policy aimed at severing outdated on-premises Exchange servers from cloud mail more sternly. The minimum version threshold has been raised, with ordinary owners of old versions no longer receiving security fixes and fresh patches available only to members of the paid Extended Security Update program. The next elevation of the minimum version will prove yet more painful, with Exchange Server 2016 and 2019 requiring a build newer than the last public update within several months, after which the extended-update program for Exchange 2016 and 2019 will conclude definitively in October 2026. This policy has emerged against the persistence of a great many vulnerable Exchange servers on the internet, with tens of thousands of servers still running outdated versions.
We recommend you to update Exchange Server 2016 and 2019 to given version link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911[/subscribe_to_unlock_form]
A vulnerability with the CVE ID CVE-2026-62911 and CVSS score of 9.8 allows access after compromise to other users' mailboxes, found in nearly 22,000 servers that had not received the fix for this issue. Microsoft's new requirements affect servers that dispatch mail to Exchange Online through an inbound connector of the OnPremises type, restricting and blocking messages from Exchange Server 2016 and 2019 unless the servers have been updated at least to the final public level of October 2025. This change is part of a broader policy aimed at severing outdated on-premises Exchange servers from cloud mail more sternly. The minimum version threshold has been raised, with ordinary owners of old versions no longer receiving security fixes and fresh patches available only to members of the paid Extended Security Update program. The next elevation of the minimum version will prove yet more painful, with Exchange Server 2016 and 2019 requiring a build newer than the last public update within several months, after which the extended-update program for Exchange 2016 and 2019 will conclude definitively in October 2026. This policy has emerged against the persistence of a great many vulnerable Exchange servers on the internet, with tens of thousands of servers still running outdated versions.
We recommend you to update Exchange Server 2016 and 2019 to given version link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]