Microsoft’s August 2026 Patch Tuesday—which we covered earlier this week for its 421 total vulnerabilities and three zero-days—contains a subset of fixes that demand immediate attention from UK SMEs running on-premises or hybrid Exchange Server deployments:
seven security vulnerabilities in Exchange Server
, including one critical flaw that security researchers successfully exploited at a public hacking competition three months ago.
For the thousands of UK small and medium-sized businesses still operating Exchange Server 2016, 2019, or 2022 for internal email, calendaring, and collaboration, this month’s updates represent an urgent patching priority.
The elevation of privilege vulnerability CVE-2026-62911 is classified as critical, and the exploitability of this flaw was successfully demonstrated in May at the Pwn2Own hacking competition in Berlin. An attacker can bypass user authentication and take control of all email accounts, send and receive emails, and download attachments.
If your organisation runs Exchange Server in any configuration—whether fully on-premises, hybrid with Microsoft 365, or hosted by a third-party provider—you need to understand what these vulnerabilities mean, which systems are affected, and what action to take this week.
Seven Exchange Server Vulnerabilities Fixed in August 2026 Patch Tuesday
Microsoft has fixed seven security vulnerabilities in Exchange Server
as part of the 11 August 2026 Patch Tuesday release. The vulnerabilities affect multiple supported versions of Exchange Server and carry severity ratings from critical to high risk.
The most serious of these flaws is CVE-2026-62911, an elevation of privilege (EoP) vulnerability that allows an attacker to bypass user authentication entirely. What makes this vulnerability particularly concerning for UK SMEs is not just its severity rating, but the fact that its exploitability has been publicly proven. Security researchers at the Pwn2Own Berlin event in May 2026 successfully demonstrated a working exploit against this flaw in a controlled competition environment.
In addition to CVE-2026-62911,
the remaining six vulnerabilities are classified as high risk, including the RCE vulnerability CVE-2026-62913
. Remote code execution (RCE) vulnerabilities allow attackers to run arbitrary code on affected servers—a capability that can lead to full system compromise, data theft, ransomware deployment, or lateral movement across your network.
Why CVE-2026-62911 Is an Immediate Patching Priority for UK SMEs
The critical Exchange Server vulnerability CVE-2026-62911 allows an attacker to completely bypass user authentication mechanisms and gain control of every email account on the affected server. Once exploited, an attacker can:
- Send and receive emails as any user in your organisation
- Download email attachments, potentially accessing sensitive business documents, contracts, financial records, and confidential communications
- Modify or delete emails to cover tracks or manipulate business processes
- Use compromised email accounts as a launchpad for business email compromise (BEC) attacks against customers, suppliers, or internal staff
- Extract credentials, calendar information, and contact lists for further attacks
The fact that this vulnerability was successfully exploited at Pwn2Own in May means that detailed knowledge of the attack methodology exists within the security research community. While Pwn2Own participants operate under responsible disclosure agreements and do not publicly release exploit code, the demonstrated feasibility of the attack significantly raises the risk that threat actors will invest effort in developing their own exploits.
For UK SMEs, this timeline matters. We are now three months past the public demonstration of this flaw and one week into the availability of patches. Any Exchange Server that remains unpatched represents an increasingly attractive target as details of the vulnerability methodology inevitably spread through attacker communities.
Exchange Server Remains a High-Value Target
Exchange Server continues to be one of the most targeted enterprise applications in the threat landscape. Email servers contain extraordinarily valuable data—everything from financial records and contracts to customer information and intellectual property. A single compromised Exchange Server can provide attackers with access to years of business communications, sensitive attachments, and the ability to impersonate anyone in your organisation.
This is why Exchange Server vulnerabilities consistently appear on lists of most-exploited flaws, and why organisations running these systems must maintain an aggressive patching cadence. As we documented in our analysis of the UK Cyber Security Breaches Survey showing 43% of businesses experienced incidents, unpatched vulnerabilities in internet-facing applications remain one of the most common initial access vectors for attackers.
Which Exchange Server Versions Are Affected?
Microsoft’s August 2026 Exchange Server updates apply to all currently supported versions of Exchange Server. If your organisation runs any of the following, you need to deploy this month’s Cumulative Updates (CUs) or Security Updates (SUs):
- Exchange Server 2019
- Exchange Server 2016
- Exchange Server 2022 (if released and supported in your environment)
Exchange Server 2013 reached end of extended support in April 2023 and no longer receives security updates from Microsoft. If you’re still running Exchange 2013 in production, these vulnerabilities—and many others discovered since April 2023—affect your environment with no patch available. Migration to a supported version or to Microsoft 365 should be your highest infrastructure priority.
Hybrid Exchange Environments Also Require Patching
Many UK SMEs operate hybrid Exchange configurations, where some mailboxes are hosted in Microsoft 365 (Exchange Online) while on-premises Exchange Server handles mail routing, directory synchronisation, or serves as a management interface for the hybrid environment.
It’s critical to understand that even if all your mailboxes have migrated to Microsoft 365, any on-premises Exchange Server still running in your environment—whether for hybrid management or legacy reasons—requires patching. These servers remain exploitable targets, and a compromised hybrid Exchange Server can provide attackers with access to your Microsoft 365 environment, directory services, and internal network.
How to Deploy August 2026 Exchange Server Security Updates
Exchange Server patching requires more planning than typical Windows updates because Exchange is a complex, business-critical application where downtime directly impacts email availability. However, the severity of this month’s vulnerabilities—particularly CVE-2026-62911—justifies prioritising this work over most other IT projects this week.
Step 1: Identify Your Exchange Server Version and Patch Level
Before you can deploy updates, you need to know exactly which version and cumulative update level your Exchange Server is currently running. You can check this by:
- Opening Exchange Admin Centre and checking the server version in the Servers section
- Running
Get-ExchangeServer | Format-List Name,Edition,AdminDisplayVersionin Exchange Management Shell - Checking the Windows Programs and Features control panel on the Exchange Server
Exchange Server uses a cumulative update model. Each CU includes all previous security fixes and feature updates. Security Updates (SUs) are smaller packages that contain only security fixes and can be installed on top of recent CUs.
Step 2: Download the Correct Update Package
Microsoft publishes Exchange Server updates through the Microsoft Update Catalog and the official Exchange Team Blog. For August 2026, you’ll need to download either:
- The latest Cumulative Update for your Exchange version (if you’re multiple CUs behind)
- The August 2026 Security Update (if you’re running a recent CU and want a faster deployment)
Make sure you download the correct package for your Exchange Server version. Installing the wrong update package can cause serious problems.
Step 3: Plan Your Maintenance Window
Exchange Server updates typically require a server restart and will interrupt email service during installation. For organisations with a single Exchange Server (common in SME environments), this means a period of email downtime.
Best practices include:
- Schedule the update outside of business hours if possible
- Notify users in advance that email will be unavailable during the maintenance window
- Allow 30–90 minutes for the update process, though actual time varies based on server specifications and update type
- Verify that you have a current, tested backup of the Exchange Server before beginning
Given the critical severity of CVE-2026-62911 and the public demonstration of its exploitability, we recommend treating this as an emergency patch deployment rather than waiting for your next scheduled maintenance window.
Step 4: Test Post-Update Functionality
After the update completes and the server restarts, verify that Exchange services are functioning correctly:
- Check that all Exchange services have started successfully
- Send and receive test emails from both internal and external addresses
- Verify that Outlook clients can connect (both internal and remote)
- Test Outlook on the Web (OWA) access
- Verify ActiveSync functionality for mobile devices
- Check Exchange Admin Centre accessibility
If you operate a hybrid Exchange environment, also verify that directory synchronisation and mail flow between on-premises and Microsoft 365 continue to function correctly.
What If You Can’t Patch Exchange Server Immediately?
In some cases, immediate patching may not be possible due to business constraints, lack of current backups, or dependencies on third-party applications that require compatibility testing. If you cannot deploy the August 2026 Exchange Server updates within the next few days, you must implement compensating controls to reduce risk:
- Restrict external access: If your Exchange Server is directly exposed to the internet, consider temporarily restricting external access to only known IP addresses (such as your VPN gateway or specific remote worker locations) until patches can be deployed
- Enhanced monitoring: Increase logging verbosity and monitor Exchange Server logs for unusual authentication patterns, unexpected administrative actions, or anomalous email activity
- Network segmentation: Ensure your Exchange Server is properly segmented from other critical systems so that a compromise doesn’t immediately provide access to your entire network
- Multi-factor authentication: Enforce MFA for all remote access to Exchange, including OWA and ECP—though note that CVE-2026-62911 involves authentication bypass, so MFA is not a complete mitigation
These measures are temporary risk reduction strategies, not substitutes for patching. Your goal should be to deploy the security updates as quickly as operationally feasible.
Consider Your Long-Term Exchange Strategy
For many UK SMEs, the ongoing operational burden of maintaining on-premises Exchange Server—including monthly security updates, infrastructure management, backup administration, and availability concerns—represents a significant and growing challenge.
Each Patch Tuesday brings new vulnerabilities that require urgent attention, often outside of business hours. Exchange Server also requires supporting infrastructure (Active Directory, DNS, certificates, load balancers, backup systems) that adds complexity and cost.
This is an appropriate time to evaluate whether on-premises or hybrid Exchange Server still makes sense for your organisation, or whether migrating fully to Microsoft 365 would reduce operational overhead while maintaining or improving functionality. As we discussed in our article on Microsoft Defender for Office 365 Plan 1 now being included in E3 licences, Microsoft 365 subscriptions now include security capabilities that many SMEs previously couldn’t afford or didn’t have the expertise to implement on-premises.
A cloud-based email approach doesn’t eliminate all security responsibilities—you still need to manage identities, enforce MFA, configure security policies, and monitor for threats—but it does shift the burden of infrastructure patching, availability, and disaster recovery to Microsoft’s cloud operations team.
Broader Patch Management Strategy Remains Essential
The August 2026 Patch Tuesday release includes
421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities
across the entire Microsoft product portfolio. Exchange Server represents just one component of this month’s security workload.
As we’ve documented throughout our August Patch Tuesday coverage, UK SMEs face an increasingly challenging patch management environment.
The total number of vulnerabilities patched by Microsoft so far this year (1,380) has already surpassed 2020’s record-breaking year (1,250)
, and we’re only in August.
This volume demands systematic approaches rather than reactive responses to individual critical vulnerabilities. Your organisation needs:
- A defined patch management policy that establishes timeframes for different severity levels
- Clear ownership and responsibility for monitoring security bulletins and deploying updates
- Testing procedures for critical systems before broad deployment
- Verification processes to confirm that patches have successfully deployed across your environment
- Compensating controls and monitoring for situations where immediate patching isn’t possible
Many Kent SMEs lack the internal resources to maintain this level of structured patch management across their entire IT estate while also handling day-to-day support requests, projects, and strategic initiatives. This is where outsourced IT support or managed service arrangements can provide significant value—not by replacing your internal team, but by augmenting capacity for specialised security tasks that require consistent execution.
Get Expert Help with Exchange Server Security and Patch Management
If your Kent or South East business runs Exchange Server and you’re concerned about this month’s critical vulnerabilities, need assistance deploying the August 2026 security updates, or want to discuss your long-term email infrastructure strategy, Meridian Micro can help.
Our team provides comprehensive IT support for SMEs across Kent and the South East, including Exchange Server management, patch deployment, Microsoft 365 migration planning, and ongoing security maintenance. We understand that small businesses need security expertise but can’t always justify full-time specialist staff—that’s exactly the gap our support services are designed to fill.
Call us on 01303 883111 to discuss your Exchange Server security concerns or to arrange a review of your current patch management processes. We can assess your environment, help you deploy this month’s critical updates, and establish systematic procedures to handle future Patch Tuesday releases more efficiently.
