Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

2026-09-01T13:23:22Z37684a0bf5b3a50b12a606d70012fb6f9c0aef4192bb98e2353c0ff0559fd5b1
ATM jackpottingCisco IOS XRClickFixGRE tunnelMicrosoft ExchangePaperCutPowerShellRhysidaTerminalFixauthentication bypasscryptocurrency exploitdata theftespionageinfostealermailbox hijackingransomwarereverse tunnelsrouter compromisesession hijackingsocial engineeringvulnerability managementzero-day exploitation

What happened

BleepingComputer reports multiple cybersecurity incidents and advisories, including nearly 22,000 internet-exposed Microsoft Exchange servers vulnerable to a high-severity authentication bypass enabling mailbox hijacking, exploitation of recently patched PaperCut zero-days for data theft, TerminalFix social engineering attacks delivering PowerShell reverse tunnels, Cisco router compromise for espionage, ransomware-related data theft, infostealer theft of Claude sessions, and major cryptocurrency and ATM attacks. The collection also includes service outages, software defects, law-enforcement,แ్

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
37684a0bf5b3a50b12a606d70012fb6f9c0aef4192bb98e2353c0ff0559fd5b1
Enrichment time
2026-09-01T13:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.