Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)

2026-09-02T20:51:40Zd399cf8c42acc4b63c25de471be210237293a57bafd4b119ca652e8dd171c7c4
CVE-2026-62911CVE-2026-83548CVE-2026-83549CVE-2026-9586ICS/OTMicrosoft ExchangeOAuth consent phishingSQL injectionSSRFSalitySangoma SwitchvoxSonicWall SMA 1000active-exploitationauthentication bypassbotnetcredential theftcritical infrastructurefraud preventionlaw enforcement disruptionremote access appliancevulnerabilityzero-day

What happened

Help Net Security reports multiple active and high-impact cyber threats, including nearly 22,000 exposed Microsoft Exchange servers affected by critical authentication-bypass CVE-2026-62911; active exploitation of a Sangoma Switchvox SQL injection vulnerability (CVE-2026-9586); and in-the-wild zero-day exploitation of SonicWall SMA 1000 flaws CVE-2026-83548 and CVE-2026-83549. Additional coverage includes OAuth consent phishing targeting prominent individuals, a battery-grid cyberattack scenario, disruption of the long-running Sality botnet, and defensive fraud and security product releases.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
d399cf8c42acc4b63c25de471be210237293a57bafd4b119ca652e8dd171c7c4
Enrichment time
2026-09-02T20:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.