Blog
Most online Exchange Servers vulnerable to ProxyLogon still not remediated
Summary: Tenable reported in January 2025 that 91% of nearly 30,000 internet-facing Microsoft Exchange Server instances it identified as vulnerable to ProxyLogon (CVE-2021-26855) had still not been remediated, almost four years after Microsoft released fixes.
Why the exposure remains serious
ProxyLogon can enable an unauthenticated attacker to reach vulnerable on-premises Exchange systems and, when chained with related flaws, gain deeper access. Public-facing email servers are especially attractive because they hold sensitive communications and can become a foothold into the wider network.
Patching may not be the final step
Installing the security update closes the vulnerable path, but it does not prove that a previously exposed server was never compromised. Organizations should also look for web shells, suspicious accounts, unexpected processes and other indicators of post-exploitation activity.
Practical takeaway
- Confirm every internet-facing Exchange server is on a supported and fully patched build.
- Follow Microsoft’s investigation and remediation guidance for potentially exposed systems.
- Review historical logs and persistence locations, not only current vulnerability scan results.
- Rotate credentials and secrets if evidence suggests the server was accessed by an attacker.
Original sources: Tenable — ProxyLogon and related Exchange vulnerabilities; Microsoft Security Response Center — investigation and remediation guidance; SC Media — Most online Exchange servers vulnerable to ProxyLogon still not remediated
Independently summarized and reviewed by CNB Telecom. Last reviewed: September 4, 2026.