Microsoft 365CIO BriefingsRetrospectives

CIO Brief: Repeated Exchange Zero-Days — A Signal to Move to the Cloud

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2021, written in 2026 with the benefit of hindsight.

The short version: In 2021, a second wave of attacks hit company-run Microsoft Exchange email servers, months after the first. Patches had been available for months. Repeated emergencies like this are a signal that running your own email servers may cost more than it's worth.

The pattern

  • March 2021: ProxyLogon, tens of thousands of servers compromised.
  • August 2021: ProxyShell, exploited for ransomware.
  • September 2022: ProxyNotShell, another emergency.

Each wave required emergency patching, investigation and, for some organizations, rebuilding servers and notifying customers.

The business impact

  • Breach and ransomware risk concentrated on a single, internet-facing system.
  • Recurring unplanned work for IT teams.
  • Opportunity cost of time spent maintaining a commodity service.

Questions to ask your team

  • How much staff time did Exchange emergencies cost us in the past two years?
  • What on-premises Exchange servers do we still run, and why?
  • Can we retire them now that Microsoft supports removing the last hybrid server?

What good looks like

Email fully in Exchange Online, on-premises servers retired, and IT time redirected to higher-value work.

The decision

Ask for a plan and date to retire your remaining Exchange servers, or a clear explanation of why you can't. Repeated emergencies are expensive.

proxyshell impactProxyShell2021

More on this story