ProxyLogon (Mar 2021): Exchange Server Zero-Days Exploited at Massive Scale
Retrospective: this article looks back at events from March 2021, written in 2026 with the benefit of hindsight.
On March 2, 2021, Microsoft released emergency patches for four zero-day vulnerabilities in on-premises Microsoft Exchange Server, collectively known as ProxyLogon (the name of the first, CVE-2021-26855). Microsoft attributed initial exploitation to a China-based group it called HAFNIUM.
What the flaws allowed
Chained together, the vulnerabilities let an unauthenticated attacker who could reach an Exchange server over HTTPS execute code on it, read mailboxes and install web shells for persistent access.
How big it got
Exploitation spread rapidly after disclosure as other groups joined in. Tens of thousands of servers worldwide were compromised within days, including many at small businesses, local governments and schools. Ransomware and crypto-mining groups followed. In April 2021, the US Department of Justice announced a court-authorized FBI operation to remove web shells from hundreds of vulnerable servers in the US — an unusual step.
Exchange Online was not affected
The vulnerabilities affected on-premises Exchange Server, not Exchange Online. Many organizations that had moved mailboxes to Microsoft 365 still ran an on-premises "hybrid" Exchange server for management, and those servers were exposed.
Lessons in hindsight
- On-premises Exchange is high-value and internet-facing — patch on an emergency timeline.
- Patching isn't enough after exploitation. Organizations had to hunt for web shells and other persistence.
- Hybrid servers count. A "management-only" Exchange server is still Exchange.
- Reduce on-premises exposure where possible.
ProxyLogon was followed by ProxyShell (2021) and ProxyNotShell (2022), and Microsoft eventually released a supported path to remove the last hybrid Exchange server for many customers. The series became one of the strongest arguments for completing the move to Exchange Online.
- How to Retire On-Premises Exchange or Harden the Hybrid Server You Must Keep How-To & Hardening
- Detecting Exchange Server Exploitation: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: The Hidden Cost of Keeping Exchange On-Prem CIO Briefings