Microsoft says 92% of vulnerable Exchange servers had been patched/mitigated, and reiterates that patches do not necessarily remove the access of the attacker
If you're cleaning up a infected Exchange server, you need to look for traces of multiple threats, warns Microsoft.
Context & Ripple Effects
Microsoft’s remediation update follows reporting that the company had taken nearly two months to release fixes after learning of the Exchange flaws and evidence that multiple, mostly state-backed groups were exploiting the vulnerabilities across thousands of servers. The patching rate therefore measures containment progress, not the end of the incident.
Microsoft’s warning shifts the operational focus from applying an update to investigating whether compromised servers still contain attacker tooling or other threats.
First-order effects
- Exchange administrators in the patched or mitigated population must perform incident-response checks, because updating a server does not by itself revoke an intruder’s existing access.
- The remaining unpatched or unmitigated Exchange servers remain the immediate exposure point while Microsoft’s reported remediation effort approaches full coverage.
Second-order effects
- Security teams and incident-response providers face a broader cleanup workload: organizations need to distinguish a closed vulnerability from a server that has already been altered by one or more attackers.
- Microsoft’s patch response is judged not only by deployment coverage but by whether customers can detect and remove persistence left behind during the mass exploitation.
Third-order effects
- The episode points to vulnerability management becoming a two-stage discipline for widely exploited enterprise software: rapid patching followed by evidence-based compromise assessment.
- Later Exchange disclosures, including two exploited zero-days in supported Exchange versions, reinforce the recurring need for organizations to maintain response capacity alongside routine patch deployment.
The trend: Mass exploitation is making patch adoption only the first step of enterprise remediation, with post-compromise investigation becoming a standard part of the response.