ISEC7 Digital Workplace Blog

Exchange ProxyLogon Zero-Days: Patch or Clash

Written by Remi Keusseyan | Mar 9, 2021, 7:30:00 AM

Editor's note, October 2026: This article was first published in March 2021 as the third part of our Security Breach series, after Security Breach: It Could Happen to You and Security Breach: Following Up 30 Days Later. The attack chain described here became known as ProxyLogon. In July 2021, the US, the EU, the UK and other governments attributed the campaign to actors affiliated with China's Ministry of State Security. All four vulnerabilities are listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and CISA closed Emergency Directive 21-02 in January 2026. The affected product versions are no longer supported: Exchange Server 2016 and 2019 reached end of support on 14 October 2025, and the current on-premises version is Exchange Server Subscription Edition (SE), available since 1 July 2025. If you still run Exchange 2016 or 2019, plan the move now.

Microsoft has released security updates for four zero-day vulnerabilities in on-premises Microsoft Exchange Server, and the Cybersecurity and Infrastructure Security Agency (CISA) has issued Emergency Directive 21-02, requiring US federal agencies to patch or disconnect affected servers.

What happened?

The four vulnerabilities are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. Attackers were exploiting them before the patches were available.

What is the impact?

By chaining these vulnerabilities, attackers can gain unauthorized access to the affected systems and potentially to the whole infrastructure and network. Because messaging servers are affected, attackers can access users' email accounts and even extract the full content of their mailboxes. Consider all the confidential and sensitive content they might reach and the damage it could cause, from financial or health records to business plans and internal communications.

Microsoft attributes the attacks to a group it calls Hafnium, which it assesses to be state-sponsored and operating out of China. According to KrebsOnSecurity, at least 30,000 organizations in the United States alone have been compromised, with many more affected worldwide.

Which products are impacted?

Several versions of on-premises Microsoft Exchange Server (2013, 2016 and 2019) are affected. Many companies, as well as many federal and government agencies, use them to host their own messaging infrastructure. Exchange Online is not affected.

What is a zero-day vulnerability?

A zero-day vulnerability is a flaw that attackers exploit before the vendor knows about it or before a patch is available. Until it is fixed, it can be used for malicious attacks, commonly called zero-day exploits or zero-day attacks.

What should I do now?

If they have not already done so, Microsoft Exchange customers need to act immediately:

  1. Patch all Exchange servers against the four vulnerabilities listed above.
  2. Check the Exchange log files for signs of compromise using the scripts Microsoft provides.
  3. Review the logs of any Endpoint Detection and Response (EDR) solution, if available.

What are the next steps?

To reduce the attack surface, avoid exposing your Microsoft Exchange servers directly to the Internet and only allow connections from trusted, pre-approved devices, for example through allowlisting. That may sound complicated with thousands of connections from desktops and mobile devices, but a Unified Endpoint Management (UEM) solution makes it manageable. Most vendors offer their own VPN-like solution or their own network infrastructure to relay traffic between endpoints and back-end servers securely, so only a few specific nodes connect directly. That limits the exposure considerably. In addition, the UEM software can pre-authorize endpoints automatically after successful enrollment, so that only secured, managed devices can connect.

Whether you plan the move to Exchange Server SE or want to tighten access to your mail infrastructure, our team supports endpoint management and endpoint security projects, and ISEC7 SPHERE monitors patch levels and known vulnerabilities of the connected systems. For why prompt patching matters in general, see Winter Is Coming, NSA Releases Top 25 Exploits. Contact us with any questions.