Key points
- On August 31, 2026, Shadowserver saw 21,899 Exchange servers unpatched against CVE-2026-62911, and more than 4 out of 5 sat in Europe and North America.
- Almost all countries with large counts are high-income economies, while Japan and India each show around 50.
- For SQL Server no public data gives an out-of-support share by country, so every national comparison rests on Exchange.
- The drivers we see are licensing models, dependencies and sovereignty rules, not low GDP.
On August 31, 2026, the Shadowserver Foundation counted at least 21,899 internet-facing Exchange servers still unpatched against CVE-2026-62911, almost 3 weeks after Microsoft shipped the fix. For Exchange 2016 and 2019 that fix comes only through paid Extended Security Updates (ESU), so the count is a fair proxy for outdated Exchange servers that run without vendor support. The top 2 countries were the United States and Germany.
The usual assumption is that old infrastructure sits in poorer markets. The scan data says the opposite, so the real question is why companies that can afford an upgrade still skip it.
Outdated Exchange servers sit mostly in Europe and North America

Both Shadowserver scans fingerprint the Exchange web front end. 2026 values come from the dashboard Shadowserver published with its post (US and Germany exact via Cybernews), 2025 values for the hybrid flaw CVE-2025-53786 via Infosecurity Magazine. SQL Server values are exposed instances of any version, not unpatched ones.
| Country | Exchange unpatched, CVE-2026-62911 (Shadowserver, Aug 31, 2026) | Exchange unpatched, CVE-2025-53786 (Shadowserver, Aug 2025) | SQL Server exposed, all versions (Shodan, Jul 17, 2026) | World Bank income group |
|---|---|---|---|---|
| North America | ||||
| United States | 6,164 | 7,296 | 27,200 | High |
| Canada | 796 | 860 | no public data | High |
| Mexico | 126 | no public data | no public data | Upper middle |
| Europe | ||||
| Germany | 5,127 | 6,682 | no public data | High |
| United Kingdom | 810 | 955 | no public data | High |
| Russia | 809 | 2,513 | no public data | High |
| Austria | 718 | 928 | no public data | High |
| France | 693 | 1,558 | no public data | High |
| Italy | 550 | no public data | no public data | High |
| Netherlands | 537 | no public data | no public data | High |
| Switzerland | 393 | no public data | no public data | High |
| Asia | ||||
| China | 353 | no public data | 43,100 | Upper middle |
| Hong Kong | 217 | no public data | no public data | High |
| South Korea | 72 | no public data | no public data | High |
| Singapore | 61 | no public data | no public data | High |
| Vietnam | 57 | no public data | no public data | Upper middle |
| India | 51 | no public data | 13,400 | Lower middle |
| Japan | 43 | no public data | no public data | High |
| Oceania | ||||
| Australia | 382 | no public data | no public data | High |
| New Zealand | 56 | no public data | no public data | High |
| South America and Africa | ||||
| Brazil | 90 | no public data | no public data | Upper middle |
| South Africa | 61 | no public data | no public data | Upper middle |
| Argentina | 56 | no public data | no public data | Upper middle |
By our addition of the dashboard values, Europe holds more than half of the 21,899 servers, the US and Canada about 32%, Asia and Oceania together around 10%. Shadowserver saw the same order in December 2023, when Europe held more than half of close to 20,000 end-of-life servers and the US 6,038 (BleepingComputer). If a continent lags, it is Europe, with North America close behind.
Public data covers Exchange and almost nothing on SQL Server
We wanted 10 countries per continent with a count and an out-of-support share. That table does not exist in public sources. A share is published only for Germany: CERT-Bund said on August 28, 2026 that around 85% of on-premises Exchange servers there were vulnerable (heise). In October 2025 the BSI knew of around 33,000 such servers in Germany (BSI), while Shadowserver counts 5,127. Neither number is the installed base.
The scan limits matter. Shadowserver sees only servers that answer from the internet, and Exchange 2013 and older are tagged separately as end of life (Shadowserver), so they are not in the CVE count. Internal Exchange is invisible. SQL Server is worse: a well-built instance never faces the internet.
For SQL Server, a Shodan query from July 17, 2026, published by a Microsoft data platform MVP, found 207,413 exposed instances (VladDBA). By our calculation, 46% run SQL Server 2014 or older, and with 2016, out of support since July 14, 2026, it is 54%. Only China, the US and India have published country totals. Top networks include Korea Telecom, Alibaba Cloud and Microsoft, so much of it sits on rented cloud machines. Inside networks, Lansweeper found 19.8% of over 1 million instances unsupported in June 2024, with no country split (The Register).
The economy does not explain the pattern
We found no published research that links Exchange or SQL Server patch rates to national income. What the data shows is the reverse of the poverty thesis: the countries with large counts are high-income economies in the World Bank classification, while India and Japan show 51 and 43. Counts mostly reflect how widely on-premises Exchange was adopted, and without a denominator no share can be calculated. The following is our assessment, not a proven correlation.
Licensing is the stronger driver. Exchange Server Subscription Edition (SE) requires subscription licences or active Software Assurance (Microsoft Product Terms). A company that bought Exchange 2016 perpetual now faces a recurring cost, priced in US dollars, to stay on premises. Waiting looks cheaper in every annual budget.
Politics removes options in some markets. Microsoft suspended all new sales in Russia on March 4, 2022 (BleepingComputer), and the World Bank has classified Russia as high income since July 2024 (World Bank). Russia’s count fell from 2,513 to 809 within a year. The data does not show whether those servers were patched, replaced or hidden. In China, Microsoft 365 is operated by 21Vianet from local data centres, under Chinese law and with a reduced feature set (Microsoft Learn). For a group with Chinese sites, that is a separate tenant and project.
Cloud is not the default exit, and the on-prem upgrade gets skipped
In a typical environment, data residency rules, regulated sectors, plants with weak connectivity, and SMTP relays for scanners, ERP and monitoring keep a server on premises. SQL Server is tied tighter: line-of-business software is certified for specific versions, so a database upgrade becomes an application project with its own vendor and budget.
Supported on-prem paths exist: Exchange SE, a newer SQL Server, or SQL Server ESU through Azure Arc, available for SQL Server 2016 until July 17, 2029 and billed pay-as-you-go (Microsoft Learn). Each needs a project owner and recurring money. A server that still delivers mail rarely wins that competition.
The Exchange risk window closes at the end of October 2026
The Exchange 2016 and 2019 ESU programme ends in October 2026, and Microsoft has said it will not be extended (Microsoft). CERT.at warned on August 27, 2026 that exploit code for CVE-2026-62911 was public (CERT.at). As of early September, Microsoft had not confirmed exploitation in the wild (iTnews).
Operationally, no support means no fix for the next flaw. In 2025, CISA ordered US federal agencies to disconnect end-of-life Exchange servers within days (CISA). Your insurer will ask the same question, see cyber insurance requirements. For the DACH detail, see our Exchange analysis for Germany, Austria and Switzerland.
Note
As of October 8, 2026. Scan counts change daily and depend on the scan definition. The table shows only values published by the named sources; “no public data” marks a gap in public sources, not zero.
What to do now
- CISO: Check your public IP ranges against Shadowserver’s free network reports and remove every Exchange web service from the internet that does not need to be there.
- CIO: Inventory every Exchange and SQL Server instance, including cloud VMs, Express editions and hybrid management servers, with version, support status and owner.
- CIO: Decide per system before the end of October 2026: Exchange Online, Exchange SE or shutdown, and for SQL Server: upgrade, Azure Arc ESU with an end date, or a managed service.
- CFO: Compare 3 years of subscription and ESU cost with migration cost, and approve no extension without a shutdown date.
- Board: Ask for a quarterly list of unsupported systems with an accountable name next to each entry.
At HACKED24 we start with read access: an inventory of Exchange, SQL Server and their dependencies, then a decision list with cost, risk and an owner per system. This is part of our Executive IT & AI Review.
Sources
- CVE-2026-62911 scan, Shadowserver, September 1, 2026
- Exchange servers exposed, Cybernews, September 1, 2026
- Servers unpatched against Exchange flaw, Infosecurity Magazine, August 12, 2025
- Vulnerable Exchange servers exposed, BleepingComputer, December 2, 2023
- 85 percent of on-prem servers in Germany vulnerable, heise online, August 31, 2026
- Microsoft Exchange warning 2025-287772-1032, BSI, October 28, 2025
- Vulnerable Exchange Server Report, Shadowserver Foundation
- Internet-exposed SQL Server instances, VladDBA, July 19, 2026
- Outdated SQL Server instances, The Register, June 17, 2024
- Income classification, World Bank, accessed October 8, 2026
- Russia classified as high-income country, World Bank, July 2, 2024
- Microsoft suspends all new sales in Russia, BleepingComputer, March 4, 2022
- Microsoft 365 operated by 21Vianet, Microsoft Learn
- Exchange Server, Microsoft Product Terms
- Exchange ESU program ends October 2026, Microsoft, 2026
- Extended Security Updates for SQL Server, FAQ, Microsoft Learn
- Exploit code for CVE-2026-62911 published, CERT.at, August 27, 2026
- Old Exchange servers remain in Australia, iTnews, September 8, 2026
- Emergency Directive 25-02, CISA, August 7, 2025



