Microsoft 365Incident TeardownsRetrospectives

ProxyShell (Aug 2021): Exchange Server Exploited Again

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2021, written in 2026 with the benefit of hindsight.

In August 2021, details emerged of ProxyShell, a chain of three vulnerabilities in on-premises Microsoft Exchange Server. Security researcher Orange Tsai presented the research at Black Hat USA. Microsoft had released patches in April and May 2021, but many servers remained unpatched.

What it allowed

Like ProxyLogon months earlier, ProxyShell let an unauthenticated attacker execute code on an internet-facing Exchange server. Within days of the details becoming public, attackers began scanning for and exploiting vulnerable servers, installing web shells. Ransomware groups including LockFile and Conti used it as an entry point.

Why so many servers were still vulnerable

The patches had been released months earlier, but:

  • Some organizations hadn't applied cumulative updates since ProxyLogon.
  • The April patches were less widely publicized as security-critical.
  • Hybrid "management" Exchange servers were overlooked.

CISA issued an urgent alert urging organizations to patch.

Why it mattered

ProxyShell showed that vulnerability research presented at conferences quickly becomes active exploitation. Patches released quietly can be as urgent as emergency ones. It also reinforced the pattern from ProxyLogon: internet-facing Exchange servers were a top target.

Lessons in hindsight

  • Patch based on exploitability, not publicity.
  • Watch CISA's Known Exploited Vulnerabilities catalog to prioritize.
  • Maintain an emergency patching process that can deploy within days.
  • Hunt after patching — patching doesn't remove web shells already installed.

ProxyNotShell followed in 2022. By then, many organizations had concluded that retiring on-premises Exchange was the only sustainable fix.

proxyshell2021

More on this story