Skip to content
Bellator Cyber Guard
News8 min readStandard

22,000 Exchange Servers Still Open to Hijack Flaw

Nearly 22,000 internet-facing Microsoft Exchange servers remain unpatched against a high-severity flaw that lets attackers hijack mailboxes.

By Bellator Cyber Guard Security Team

What happened

Security researchers reported this week that nearly 22,000 internet-facing Microsoft Exchange servers remain unpatched against a high-severity authentication bypass vulnerability, leaving them open to mailbox hijacking attacks. Microsoft Exchange Server is the on-premises email and calendaring platform many organizations run in-house instead of, or alongside, cloud-hosted Exchange Online in Microsoft 365. An authentication bypass vulnerability is a flaw that lets an attacker skip normal login verification, in this case reportedly allowing full access to user mailboxes without valid credentials.

According to the report, the exposed servers were identified through internet-wide scanning, meaning they are directly reachable from the public internet rather than shielded behind a VPN, firewall rule, or internal network boundary. That distinction matters: internet-facing Exchange servers are the ones attackers can probe and exploit remotely, without needing a foothold inside the network first. The affected count reportedly spans organizations of many sizes, a pattern consistent with prior Exchange vulnerabilities that have been mass-exploited within days of public disclosure.

Bellator Cyber Guard has not independently verified the specific CVE identifier, patch release date, or exploitation status tied to this report, and those details were not included in the source material we reviewed. Readers should check Microsoft's own advisory channels directly for the exact vulnerability identifier and applicable patch before taking action, since acting on an unconfirmed CVE risks applying the wrong fix.

Key Takeaway

If your organization still runs on-premises Microsoft Exchange, treat any internet-facing server as a priority patching target this week. Confirm your exact patch level against Microsoft's Security Update Guide, and if you cannot verify the server is current, restrict external access until it is.

Why this keeps happening to Exchange

On-premises Exchange servers have been one of the most consistently targeted pieces of enterprise infrastructure over the past several years, and the pattern behind that isn't mysterious. Exchange sits at a uniquely valuable position in most networks: it holds every employee's email history, calendar, and often serves as a trusted authentication point tied into Active Directory. A successful mailbox hijack doesn't just expose one inbox, it can hand an attacker a platform for business email compromise, internal phishing that looks legitimate because it comes from a real coworker's account, and a foothold for lateral movement deeper into the network.

The scale of unpatched exposure reported here, nearly 22,000 servers, also reflects a structural problem rather than a one-time lapse. Exchange patching is disruptive. It often requires maintenance windows, testing against custom mail flow rules, and coordination with third-party plugins or compliance archiving tools that many healthcare practices, accounting firms, and law offices depend on. That friction is exactly why threat actors watch for Exchange advisories and build exploitation tooling quickly; they know a meaningful share of exposed servers will still be unpatched weeks or months later.

It's also worth noting what this kind of vulnerability class typically enables once exploited. Authentication bypass flaws in mail servers have historically been chained with follow-on techniques, web shell deployment, credential harvesting, or mailbox rule manipulation that silently forwards sensitive email to an attacker-controlled address. Even organizations with strong endpoint protection can be blindsided if the compromise starts at the mail server layer, since that traffic often looks like normal business email activity to downstream security tools.

What this means for your business

If you operate on-premises Exchange, or manage IT for clients who do, treat this report as a prompt to verify, not assume, your patch status. A few concrete steps:

  • Confirm exposure first. Check whether your Exchange server's web interface (OWA, ECP) is reachable directly from the public internet, and if so, whether that's actually necessary. Where possible, require VPN or a reverse proxy with additional authentication in front of it.
  • Verify patch level against Microsoft's official guidance. Don't rely on memory of "we patched last quarter." Confirm the current cumulative update and any relevant security patches are actually installed, since Exchange updates are cumulative and a missed step can leave systems partially patched.
  • Review mailbox and transport rules. After any suspected exposure window, check for unfamiliar inbox forwarding rules, new delegate access, or transport rules that silently copy or redirect mail, a common sign of prior mailbox compromise.
  • Enable and review authentication logs. Unusual login patterns, especially from unfamiliar geographic locations or impossible-travel logins, are often the earliest signal of a hijacked mailbox.
  • Consider your long-term platform strategy. Organizations still running on-premises Exchange should weigh the ongoing patching burden against migrating to Exchange Online, where Microsoft manages the underlying server patching directly. This isn't the right call for every organization, but it's a conversation worth having given how frequently on-prem Exchange has been targeted in recent years.

For healthcare practices and tax professionals specifically, a hijacked mailbox is also a compliance exposure. Email is a common repository for patient records or client financial data, and unauthorized mailbox access can trigger breach notification obligations under HIPAA or state data breach laws depending on what the mailbox contained. Documenting your patch cadence and access controls now, before an incident, not after, makes that conversation with regulators or auditors far easier if it's ever needed.

Small businesses without dedicated IT security staff should treat "we're not sure if we're patched" as itself a red flag. If your organization can't quickly answer whether your Exchange servers are current, that's a strong signal it's time to bring in a managed service provider or security consultant to run a rapid assessment, particularly given how quickly attackers have historically weaponized Exchange vulnerabilities once details become public.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

People also look for

Keep exploring Phishing & email security

Recognize manipulation, protect email accounts, and give people a clear way to report suspicious messages.

Learn first. Decide when you are ready.

Keep learning—or apply this to your situation

Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.