PGH Networks

22,000 Exchange Servers Still Exposed: What Pittsburgh SMBs Should Do

September 2, 2026· PGH Networks Team· 5 min readManaged IT
22,000 Exchange Servers Still Exposed: What Pittsburgh SMBs Should Do

What happened

BleepingComputer reports that nearly 22,000 Microsoft Exchange servers exposed to the internet remain unpatched against a high-severity authentication bypass flaw. According to the reporting, successful exploitation lets an attacker hijack every user mailbox on the affected server, which is about as bad as an email compromise gets.

An authentication bypass means the attacker does not need a stolen password, a phished MFA code, or an insider. If your organization still runs an on-premises Exchange server, or keeps one around in a hybrid configuration for mail flow and attribute management, this belongs at the top of your list this week. The specific CVE, affected build numbers, and whether any mitigation exists short of patching are details you should confirm directly against Microsoft's advisory and the source article rather than take from a summary, ours included.

cable network

Why this matters for the audience

Around Pittsburgh, we still see more on-prem and hybrid Exchange than most people expect. A 40-person CPA firm in the South Hills that migrated mailboxes to the cloud years ago but never decommissioned the last Exchange box. A manufacturer in the Mon Valley whose ERP and shop-floor scanners hand off notifications to an internal server nobody has logged into since a staff change. A law firm that keeps hybrid Exchange because that is how directory sync was set up during the original project and nobody wanted to touch it. Those servers are still internet-facing, still patch-eligible, and still fully trusted by your Microsoft 365 tenant.

That trust relationship is the part that stings. Hybrid Exchange servers hold privileged permissions into the cloud tenant. A takeover on-prem is not contained to on-prem. Full mailbox access means attackers can read years of partner correspondence, monitor client threads to find the moment money moves, and inject a fraudulent wire instruction in a reply that looks exactly like your accountant. Legal and financial services firms in this region get hit with that pattern regularly, and the dollar losses are rarely covered as cleanly as clients assume.

The compliance math is just as unpleasant. For healthcare clients, unauthorized access to mailboxes containing PHI is a reportable HIPAA breach event, and "we never patched it" is not a defense that survives an OCR inquiry. Financial services and CPA firms under FTC Safeguards are expected to have documented vulnerability management. Defense contractors pursuing or maintaining CMMC Level 2 will find flaw remediation and boundary protection sitting right there in the control set, and email frequently carries CUI whether policy says it should or not. If you are heading into a SOC 2 audit, an unpatched internet-facing mail server is the kind of finding that turns a clean report into a qualified one.

What to do about it

  1. Confirm whether you actually have an Exchange server, today. Not "I think we're all cloud." Check for on-prem Exchange, hybrid servers, and any decommissioned-in-name-only box that still answers on 443. If your IT provider cannot answer this within an hour from asset inventory, that is its own finding.
  2. Patch to the current supported cumulative update and security update. Verify the required build against Microsoft's advisory before you schedule the window, since Exchange updates often have prerequisite CU levels. Plan for a reboot and a short mail-flow interruption, and validate hybrid mail flow afterward.
  3. Get Exchange off the open internet where you can. If the server exists only for hybrid attribute management or an internal application relay, restrict inbound access to Microsoft's published service endpoints and your own networks. Fewer exposed surfaces beats faster patching every time.
  4. Hunt before you assume you're clean. Review mailbox audit logs, tenant sign-in logs, and Exchange transport rules for the last 90 days, back to early June. Look for new or modified inbox rules that forward or delete mail, unexpected mailbox delegate permissions, and outbound rules routing copies to external addresses. Exfiltration through a mailbox rule is quiet and common.
  5. Rotate credentials tied to the server. Service accounts, connector credentials, and any privileged account that authenticated to Exchange during the exposure window. Assume secrets on a compromised host are no longer secrets.
  6. Build the decommissioning plan. For most 10 to 200 employee organizations, the durable fix is retiring on-prem Exchange entirely and moving directory sync to Entra Connect cloud sync. That is a project, not an afternoon, so it belongs on your technology roadmap with a real target date this quarter, not a someday list.
  7. Verify patch coverage is measured, not assumed. Ask for a report showing every server and endpoint, its patch level, and the last successful cycle. Effective patch management produces evidence you can hand to an auditor, and it should cover servers and network appliances, not just workstations.

One more note, since it comes up in nearly every strategy conversation now: firms rushing to deploy Microsoft 365 Copilot should understand that Copilot inherits your existing permissions model. If mailboxes and SharePoint sites are over-shared or a mail server is compromised, AI tooling makes that exposure faster to reach, not safer. Fixing identity and patch hygiene is the actual first step of any honest Copilot readiness effort.

How we help

PGH Networks handles patch management, vulnerability remediation, and hybrid Exchange decommissioning for small and mid-sized organizations across Western Pennsylvania, backed by cybersecurity monitoring that watches for mailbox rule abuse and suspicious sign-ins rather than waiting for a client to notice a forged invoice. If you are in a regulated vertical, we map that work to the framework you actually answer to, so remediation produces audit evidence instead of just a closed ticket.

Want a straight answer on whether you have an exposed Exchange server and what it would take to retire it? Call us at 724.888.7007 or reach out through the contact form, and we will scope it this week.

Share

Related reading

Choosing an MSP for a Pittsburgh Law Firm

How Pittsburgh law firms should evaluate a managed service provider: ABA 477R duty of competence, legal-app expertise, 24/7 security, and local response.

Call usBook a meeting