Blogs

Most online Exchange Servers vulnerable to ProxyLogon still not remediated

Microsoft Exchange Server security and ProxyLogon vulnerability illustration

Summary: Tenable reported in January 2025 that 91% of nearly 30,000 internet-facing Microsoft Exchange Server instances it identified as vulnerable to ProxyLogon (CVE-2021-26855) had still not been remediated, almost four years after Microsoft released fixes.

Why the exposure remains serious

ProxyLogon can enable an unauthenticated attacker to reach vulnerable on-premises Exchange systems and, when chained with related flaws, gain deeper access. Public-facing email servers are especially attractive because they hold sensitive communications and can become a foothold into the wider network.

Patching may not be the final step

Installing the security update closes the vulnerable path, but it does not prove that a previously exposed server was never compromised. Organizations should also look for web shells, suspicious accounts, unexpected processes and other indicators of post-exploitation activity.

Practical takeaway

  • Confirm every internet-facing Exchange server is on a supported and fully patched build.
  • Follow Microsoft’s investigation and remediation guidance for potentially exposed systems.
  • Review historical logs and persistence locations, not only current vulnerability scan results.
  • Rotate credentials and secrets if evidence suggests the server was accessed by an attacker.

Original sources: Tenable — ProxyLogon and related Exchange vulnerabilities; Microsoft Security Response Center — investigation and remediation guidance; SC Media — Most online Exchange servers vulnerable to ProxyLogon still not remediated

Independently summarized and reviewed by CNB Telecom. Last reviewed: September 4, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *