Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
2026-09-02T14:51:48Z•27f1147fa96ad3e5a575a787df6e80fcc090275659c6efc2d6df142e5b790e5c
CVE-2026-62911CVE-2026-83548CVE-2026-83549CVE-2026-9586Microsoft ExchangeOAuth consent phishingSQL injectionSSL VPNSSRFSalitySangoma SwitchvoxSonicWall SMA 1000active exploitationauthentication bypassbotnet disruptioncritical vulnerabilityinternet-exposed systemszero-day
What happened
Help Net Security reports multiple active cybersecurity threats: nearly 22,000 Microsoft Exchange servers remain exposed to critical authentication-bypass CVE-2026-62911; attackers are exploiting Sangoma Switchvox SQL injection CVE-2026-9586; and SonicWall SMA 1000 appliances are under active zero-day attack involving pre-authentication SSRF CVE-2026-83548 and CVE-2026-83549. The feed also covers OAuth consent phishing targeting prominent individuals, disruption of the Sality botnet, and broader cyber-risk developments.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 27f1147fa96ad3e5a575a787df6e80fcc090275659c6efc2d6df142e5b790e5c
- Enrichment time
- 2026-09-02T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.