Microsoft Exchange Zero-Day: No Patch, Active Exploitation, Vendor Silence

Microsoft Exchange has an actively exploited zero-day. As of early August 2026, there is no patch.

Enterprise email infrastructure is under attack right now, and the vendor has not told you how to stop it.

Exchange runs the email for a massive portion of corporate and government organizations. When a zero-day hits Exchange, it's not hitting one company – it's hitting every organization running that software. And when there's no patch, defenders have no move.

Attackers are exploiting this vulnerability in the wild. That means actual organizations, with actual email systems, are being compromised right now. Microsoft knows. The security research community knows. Enterprises running Exchange know they're exposed.

What they don't know is how to fix it, because Microsoft hasn't released a patch or published effective mitigation steps.

The pattern is familiar. A critical vulnerability in enterprise infrastructure gets discovered. Attackers exploit it before the vendor patches it. Organizations running the vulnerable software scramble to figure out if they've been compromised and what they can do to stop further exploitation. The vendor says they're "working on a fix." Days or weeks pass. Incidents pile up.

Zero-days with no available mitigation put defenders in an impossible position. You can't patch what doesn't have a patch. You can monitor for indicators of compromise, but if you don't know what the attack looks like, you don't know what to monitor for. You can isolate systems, but email is business-critical – shutting down Exchange shuts down the organization.

So you wait. You watch. You hope you're not next. And you plan the incident response you'll need when waiting and hoping don't work.

Microsoft's response timing matters here. Every day without a patch is another day attackers have free run of unpatched Exchange servers. Every organization still running vulnerable Exchange is counting on Microsoft to release a fix before an attacker pivots from email access to domain admin, lateral movement, and exfiltration.

Exchange has been a target before. ProxyLogon, ProxyShell, ProxyNotShell – Exchange vulnerabilities have been exploited at scale, often by nation-state actors and ransomware groups. A zero-day with no patch in August 2026 fits the pattern: high-value target, broad install base, enterprise email as the pivot point into the network.

The lack of detail is deliberate. Vendors withhold specifics about unpatched vulnerabilities to slow attacker adoption. But that calculation assumes attackers don't already have the exploit – and in a zero-day scenario where active exploitation is confirmed, attackers already have it. The information asymmetry isn't protecting anyone. It's just keeping defenders in the dark.

Organizations running Exchange need to assume they're exposed and plan accordingly. Monitor for unusual authentication patterns, unexpected mailbox access, privilege escalation attempts. Review Exchange logs for anomalies. Have an IR plan that accounts for email infrastructure compromise. Know your recovery point objectives and have offline backups that an attacker with Exchange access can't reach.

And wait for Microsoft to release the patch.

The zero-day window is the most dangerous phase of any vulnerability's lifecycle. The vulnerability is known. Attackers are exploiting it. No fix is available. Defenders are flying blind.

Microsoft has not disclosed the attack vector, the affected Exchange versions, or a timeline for the patch. That silence is standard practice for unpatched vulnerabilities, but it leaves defenders with nothing actionable. "Be vigilant" is not a security control.

Enterprise email is not optional. Exchange downtime is business downtime. So organizations keep running the vulnerable servers because the alternative is shutting down email, and that's not a choice most can make.

That's the leverage attackers have. That's why Exchange is a target. And that's why a zero-day with no patch is not just a technical problem – it's an organizational crisis waiting to happen.

If you're running Exchange, you're exposed. If you've been compromised, you may not know it yet. And if Microsoft doesn't release a patch soon, the exposure window keeps growing.

The vendor has one job here: release the patch, release effective mitigations, or tell defenders exactly what they're up against so they can make informed decisions about risk. Silence is not a security strategy. It's liability dressed as caution.

Enterprises deserve better. They're paying for Exchange. They're trusting Microsoft to secure it. And right now, they're exposed to an actively exploited zero-day with no fix and no timeline.

That's not acceptable. And it's not new. It's the same pattern that's played out with every major Exchange vulnerability – except this time, the patch still isn't here.