RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Vulnerability

Vulnerability / From the archive · 2 March 2021 event · prepared 16 September 2026

Unpatched Exchange servers fell within days of a March 2021 fix

An emergency directive followed mass web-shell exploitation of on-premises Exchange flaws Microsoft patched on 2 March 2021.

Visual for this record: Unpatched Exchange servers fell within days of a March 2021 fix
Visual published by microsoft.com, shown for identification of the record. Credit: microsoft.com · source page ↗ Rights: owner-review-pending.

What happened

On 2 March 2021, Microsoft released out-of-band security updates for four vulnerabilities in on-premises Exchange Server, writing in its own disclosure that limited, targeted exploitation was already under way. The next day the Cybersecurity and Infrastructure Security Agency issued Emergency Directive 21-02, ordering federal civilian agencies to identify every on-premises Exchange server, run forensic checks for existing compromise, patch or disconnect it, and report results within days. Exploitation moved faster than most organisations could patch. CISA's updated advisory records that intruders who reached a server before an update was applied often left behind web shells, small scripts that grant an attacker continued remote access independent of the vulnerability that let them in, so a server patched after compromise could remain under someone else's control.

Confidence and limits

Microsoft's disclosure and two CISA products describe the same four vulnerabilities, the same 2 March patch date, and the same web-shell persistence pattern, so the technical sequence is well corroborated by parties with direct visibility into it. Attribution is a separate, later-added layer. Microsoft named the initial campaign HAFNIUM with high confidence at the time of disclosure. Four months on, the US government's updated advisory states that it attributes the broader activity to actors affiliated with the People's Republic of China's Ministry of State Security. That is an official government assessment, not a court finding, and neither document quantifies how many organisations worldwide were ultimately compromised, since the exposed flaw drew in additional, unrelated actors once details became public.

Why it mattered

The directive marked a shift in how the government treats a mass-exploited, internet-facing product: patching was declared necessary but not sufficient, and agencies were told to assume prior compromise and hunt for evidence of it before trusting a newly patched server. That patch-then-hunt sequence became a template later applied to other widely used on-premises software. The episode also underlined a structural difference from cloud services: a vendor can push an update centrally to a hosted product, but an on-premises server depends on its own operator noticing an advisory, scheduling downtime and applying the fix before an automated scan finds it first.

Defensive takeaway

If you operate on-premises Exchange, or any comparable internet-facing on-premises product with a history of mass exploitation, check not only whether current patches are installed but whether independent indicators of past compromise are present, since a patch applied after intrusion does not remove a web shell placed beforehand.

  • Do you maintain a current inventory of every internet-facing on-premises server, including ones no one actively monitors?
  • Would your team recognise a newly created web shell or administrative account predating a patch?
  • Who is responsible for reading vendor and CISA advisories on the day they are issued, and what happens next?

The lesson was not that Exchange was uniquely fragile but that any on-premises system reachable from the internet inherits its operator's patching discipline as part of its threat model, and a vendor's patch date marks the start of a defender's work rather than the end of it.

Defensive takeaway

If you operate on-premises Exchange or a comparable internet-facing product, check for independent indicators of prior compromise in addition to confirming current patches, since patching alone does not remove a web shell placed beforehand.

Microsoft's own disclosure and two CISA products agree on the vulnerabilities, patch date and web-shell activity. The China-nexus attribution, added by the US government four months later, is stated as an official assessment rather than a court-established fact, and total victim counts are not established by either source.

Sources & reading trail

ED 21-02: Mitigate Microsoft Exchange On-Premises Product Vulnerabilities ↗

Establishes the emergency directive's date, its forensic-triage and patch requirements, and agency reporting deadlines.

government-primary · Source published: 3 March 2021 · Retrieved: 16 September 2026

HAFNIUM Targeting Exchange Servers With 0-day Exploits ↗

Microsoft's own disclosure of the four vulnerabilities, the patch release, and its high-confidence attribution of initial activity to HAFNIUM.

vendor-primary · Source published: 2 March 2021 · Retrieved: 16 September 2026

Mitigate Microsoft Exchange Server Vulnerabilities (AA21-062A) ↗

Describes the web-shell persistence mechanism at a defender-relevant level and records the US government's July 2021 attribution to PRC-affiliated actors.

government-primary · Source published: 3 March 2021 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.