HACKED24, Autonomous Enterprise IT

Most outdated Exchange servers sit in high-income economies

Scan data puts most outdated Exchange servers in Europe and North America, not in poorer markets. Licensing and dependencies explain more than GDP.

David Lorenz
Oct 8, 20267 min read
A white ceramic hemisphere covered in small hexagonal tiles, a few raised tiles in brushed aluminium lit from below in indigo and cyan, on a light grey background.

Key points

  • On August 31, 2026, Shadowserver saw 21,899 Exchange servers unpatched against CVE-2026-62911, and more than 4 out of 5 sat in Europe and North America.
  • Almost all countries with large counts are high-income economies, while Japan and India each show around 50.
  • For SQL Server no public data gives an out-of-support share by country, so every national comparison rests on Exchange.
  • The drivers we see are licensing models, dependencies and sovereignty rules, not low GDP.

On August 31, 2026, the Shadowserver Foundation counted at least 21,899 internet-facing Exchange servers still unpatched against CVE-2026-62911, almost 3 weeks after Microsoft shipped the fix. For Exchange 2016 and 2019 that fix comes only through paid Extended Security Updates (ESU), so the count is a fair proxy for outdated Exchange servers that run without vendor support. The top 2 countries were the United States and Germany.

The usual assumption is that old infrastructure sits in poorer markets. The scan data says the opposite, so the real question is why companies that can afford an upgrade still skip it.

Outdated Exchange servers sit mostly in Europe and North America

World map with bubbles sized by the number of Exchange servers unpatched against CVE-2026-62911 per country, largest in the United States and Germany
Internet-visible Exchange servers still unpatched against CVE-2026-62911, by country. Source: Shadowserver Foundation, scan of 31 August 2026.

Both Shadowserver scans fingerprint the Exchange web front end. 2026 values come from the dashboard Shadowserver published with its post (US and Germany exact via Cybernews), 2025 values for the hybrid flaw CVE-2025-53786 via Infosecurity Magazine. SQL Server values are exposed instances of any version, not unpatched ones.

Country Exchange unpatched, CVE-2026-62911 (Shadowserver, Aug 31, 2026) Exchange unpatched, CVE-2025-53786 (Shadowserver, Aug 2025) SQL Server exposed, all versions (Shodan, Jul 17, 2026) World Bank income group
North America
United States 6,164 7,296 27,200 High
Canada 796 860 no public data High
Mexico 126 no public data no public data Upper middle
Europe
Germany 5,127 6,682 no public data High
United Kingdom 810 955 no public data High
Russia 809 2,513 no public data High
Austria 718 928 no public data High
France 693 1,558 no public data High
Italy 550 no public data no public data High
Netherlands 537 no public data no public data High
Switzerland 393 no public data no public data High
Asia
China 353 no public data 43,100 Upper middle
Hong Kong 217 no public data no public data High
South Korea 72 no public data no public data High
Singapore 61 no public data no public data High
Vietnam 57 no public data no public data Upper middle
India 51 no public data 13,400 Lower middle
Japan 43 no public data no public data High
Oceania
Australia 382 no public data no public data High
New Zealand 56 no public data no public data High
South America and Africa
Brazil 90 no public data no public data Upper middle
South Africa 61 no public data no public data Upper middle
Argentina 56 no public data no public data Upper middle

By our addition of the dashboard values, Europe holds more than half of the 21,899 servers, the US and Canada about 32%, Asia and Oceania together around 10%. Shadowserver saw the same order in December 2023, when Europe held more than half of close to 20,000 end-of-life servers and the US 6,038 (BleepingComputer). If a continent lags, it is Europe, with North America close behind.

Public data covers Exchange and almost nothing on SQL Server

We wanted 10 countries per continent with a count and an out-of-support share. That table does not exist in public sources. A share is published only for Germany: CERT-Bund said on August 28, 2026 that around 85% of on-premises Exchange servers there were vulnerable (heise). In October 2025 the BSI knew of around 33,000 such servers in Germany (BSI), while Shadowserver counts 5,127. Neither number is the installed base.

The scan limits matter. Shadowserver sees only servers that answer from the internet, and Exchange 2013 and older are tagged separately as end of life (Shadowserver), so they are not in the CVE count. Internal Exchange is invisible. SQL Server is worse: a well-built instance never faces the internet.

For SQL Server, a Shodan query from July 17, 2026, published by a Microsoft data platform MVP, found 207,413 exposed instances (VladDBA). By our calculation, 46% run SQL Server 2014 or older, and with 2016, out of support since July 14, 2026, it is 54%. Only China, the US and India have published country totals. Top networks include Korea Telecom, Alibaba Cloud and Microsoft, so much of it sits on rented cloud machines. Inside networks, Lansweeper found 19.8% of over 1 million instances unsupported in June 2024, with no country split (The Register).

The economy does not explain the pattern

We found no published research that links Exchange or SQL Server patch rates to national income. What the data shows is the reverse of the poverty thesis: the countries with large counts are high-income economies in the World Bank classification, while India and Japan show 51 and 43. Counts mostly reflect how widely on-premises Exchange was adopted, and without a denominator no share can be calculated. The following is our assessment, not a proven correlation.

Licensing is the stronger driver. Exchange Server Subscription Edition (SE) requires subscription licences or active Software Assurance (Microsoft Product Terms). A company that bought Exchange 2016 perpetual now faces a recurring cost, priced in US dollars, to stay on premises. Waiting looks cheaper in every annual budget.

Politics removes options in some markets. Microsoft suspended all new sales in Russia on March 4, 2022 (BleepingComputer), and the World Bank has classified Russia as high income since July 2024 (World Bank). Russia’s count fell from 2,513 to 809 within a year. The data does not show whether those servers were patched, replaced or hidden. In China, Microsoft 365 is operated by 21Vianet from local data centres, under Chinese law and with a reduced feature set (Microsoft Learn). For a group with Chinese sites, that is a separate tenant and project.

Cloud is not the default exit, and the on-prem upgrade gets skipped

In a typical environment, data residency rules, regulated sectors, plants with weak connectivity, and SMTP relays for scanners, ERP and monitoring keep a server on premises. SQL Server is tied tighter: line-of-business software is certified for specific versions, so a database upgrade becomes an application project with its own vendor and budget.

Supported on-prem paths exist: Exchange SE, a newer SQL Server, or SQL Server ESU through Azure Arc, available for SQL Server 2016 until July 17, 2029 and billed pay-as-you-go (Microsoft Learn). Each needs a project owner and recurring money. A server that still delivers mail rarely wins that competition.

The Exchange risk window closes at the end of October 2026

The Exchange 2016 and 2019 ESU programme ends in October 2026, and Microsoft has said it will not be extended (Microsoft). CERT.at warned on August 27, 2026 that exploit code for CVE-2026-62911 was public (CERT.at). As of early September, Microsoft had not confirmed exploitation in the wild (iTnews).

Operationally, no support means no fix for the next flaw. In 2025, CISA ordered US federal agencies to disconnect end-of-life Exchange servers within days (CISA). Your insurer will ask the same question, see cyber insurance requirements. For the DACH detail, see our Exchange analysis for Germany, Austria and Switzerland.

Note

As of October 8, 2026. Scan counts change daily and depend on the scan definition. The table shows only values published by the named sources; “no public data” marks a gap in public sources, not zero.

What to do now

  1. CISO: Check your public IP ranges against Shadowserver’s free network reports and remove every Exchange web service from the internet that does not need to be there.
  2. CIO: Inventory every Exchange and SQL Server instance, including cloud VMs, Express editions and hybrid management servers, with version, support status and owner.
  3. CIO: Decide per system before the end of October 2026: Exchange Online, Exchange SE or shutdown, and for SQL Server: upgrade, Azure Arc ESU with an end date, or a managed service.
  4. CFO: Compare 3 years of subscription and ESU cost with migration cost, and approve no extension without a shutdown date.
  5. Board: Ask for a quarterly list of unsupported systems with an accountable name next to each entry.

At HACKED24 we start with read access: an inventory of Exchange, SQL Server and their dependencies, then a decision list with cost, risk and an owner per system. This is part of our Executive IT & AI Review.

David Lorenz

Founder and Managing Partner of HACKED24. More than 20 years in enterprise IT architecture, security and operations.

Want to see what this means for your IT?

Every enquiry is answered personally, usually on the same business day.