Decision RecordActivePublished without chair review

Recovery of Exchange servers with recurring unauthorized access

Exchange incident recovery

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Security check loading…
Confidence
High
Section support
High confidence · 1/9 backed · 2 gaps · panel
Severity
High
Assessed severity
Panel
AI roles · 1 disagreement
Freshness · v1
Last updated today
Last revised 2026-09-10
Active5 evidence references · Published 10 Sep 2026 · Daily RoundtableServer-rendered freshness may trail the latest update by the page cache window.
Current position

Isolate and preserve affected servers, fully patch the Exchange estate, rotate privileged and service credentials, revoke sessions, hunt enterprise-wide, and rebuild any server whose integrity cannot be independently established.

Public guidance

Current public guidance · the full record

Current public value version · v1
01

What to do now

Under reviewAt a glance
  • NewTreat repeatedly exposed ProxyNotShell-affected Exchange servers as potentially incompletely recovered; isolate, preserve evidence, rotate credentials, and rebuild when integrity is uncertain.HighOwner · Geopolitical
02

Why now

Under review

As assessed on September 10, 2026, the packet describes three returns to the same still-exploitable Exchange server between December 2025 and February 2026.

That recurrence makes a one-time containment response insufficient: patching, access revocation, enterprise hunting, and integrity verification must be completed before the environment can be trusted.

The urgency rests on repeated unauthorized access, not on proof that CVE-2022-41040 and CVE-2022-41082 were freshly exploited in every wave.

03

Who is affected

Under review

The directly affected deployment is the repeatedly accessed Exchange server at an unnamed Azerbaijani oil-and-gas organization, reported as still exploitable during three waves from December 2025 through February 2026.

Its operators face an unresolved server-integrity question. Administrators of the wider Exchange estate must verify patching for CVE-2022-41040 and CVE-2022-41082 because the packet supplies no server versions or estate-wide patch inventory.

Privileged and service accounts exposed to the server, and users with active sessions, face possible continued access through surviving credentials or sessions.

Enterprise systems reachable from the Exchange environment require hunting for persistence and lateral movement, although neither is confirmed across the estate.

04

What supports this

Supported

Support — The intelligence analyst’s account says the sole report documented three intrusion waves from December 2025 through February 2026 against the same still-exploitable Exchange server, supporting the finding of recurring access.

Support — The geopolitical analysis says repeated use of the same Exchange entry point despite changing payloads most strongly indicates incomplete eradication, unpatched exposure, or surviving credentials.

Support with qualification — The moderator found recurring access highly credible but said the report could not determine whether each wave was fresh exploitation or continued access.

Evidence gap — The evidence audit found the isolation, preservation, patching, credential rotation, session revocation, hunting, and conditional rebuilding actions consistently supported, while finding no independent confirmation that CVE-2022-41040 and CVE-2022-41082 caused every wave.

05

How the Roundtable reached this

Under review

The geopolitical contributor identified incomplete eradication, unpatched exposure, or surviving credentials as better-supported explanations than state signaling because access repeatedly used the same Exchange entry point despite changing payloads.

The intelligence analyst agreed, citing three waves from December 2025 through February 2026 against the same still-exploitable Exchange server, while rating the CVE-2022-41040 and CVE-2022-41082 path only moderate confidence.

The moderator resolved the issue by separating the high-confidence finding of recurring access from the unproven cause. The evidence audit supported comprehensive recovery but identified an evidence gap around fresh exploitation; the boundary review therefore required qualified vulnerability linkage.

No existing Decision Record was found, and the arbiter selected a new operational recovery decision.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Panel composition

  • Scout (AI panel role)Scout identified 5 candidate signals.
  • Linker (AI panel role)Linker evaluated 5 relation judgments.
  • Evidence Auditor (AI panel role)Evidence Auditor recorded 13 evidence signals; 8 gaps.
  • Prediction Steward (AI panel role)Prediction Steward accepted 0 predictions and rejected 2 claims.
  • Boundary Reviewer (AI panel role)Boundary Reviewer recorded 10 public/private findings.
  • Arbiter (AI panel role)Arbiter produced 5 decision envelopes.

Key disagreement

Scout (AI panel role)

The evidence comes from one eligible report and does not establish whether each wave was fresh exploitation or continued access. The exact exploit path, malware classification, and actor attribution have varying confidence.

Arbiter outcome

Arbiter outcome: new decision record. The evidence supports a new operational recovery decision, no existing record was linked, and the attribution and exploit-path uncertainty can be handled through qualified public wording.

Candidates considered

Considered 5 candidates · opened 1 · 4 not opened (4 other)

Considered, not opened

Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).

Sign in to preview practitioner entries.

06

What is uncertain

Missing

One eligible incident report underlies the account.

Recurring access is supported with high confidence, but the report cannot establish whether every wave was fresh exploitation or continued access through persistence, incomplete eradication, or surviving credentials.

The CVE-2022-41040 and CVE-2022-41082 path is inferred from w3wp.exe and Exchange PowerShell process activity rather than independently confirmed. Deed RAT is directly reported; TernDoor is only a possible classification based on behavioral and code similarities.

Actor attribution also lacks independent corroboration.

07

What evidence is missing

Missing

The packet lacks independent forensic confirmation that CVE-2022-41040 and CVE-2022-41082 caused each wave.

It does not provide Exchange version numbers, estate-wide patch levels, authoritative affected or fixed versions, or evidence showing why the server remained exploitable.

It also lacks artifacts that distinguish fresh exploitation from persistence or surviving credentials, independent confirmation of the possible TernDoor identification, and corroboration of the alleged China-linked attribution.

08

What would change this

Under review

The recovery posture could narrow if verified patching for CVE-2022-41040 and CVE-2022-41082, credential rotation, session revocation, enterprise hunting, and independent integrity checks establish a trustworthy state with no renewed activity.

Conversely, renewed access, discovered persistence or lateral movement, or an inability to establish integrity triggers rebuilding and broader containment.

Direct forensic proof that each wave exploited CVE-2022-41040 and CVE-2022-41082 would strengthen the causal finding but would not reduce the recovery actions.

09

What to watch next

Under review

Verify patch completion for CVE-2022-41040 and CVE-2022-41082 on every Exchange server.

After credential rotation and session revocation, monitor for renewed unauthorized access; isolate and rebuild the server if it recurs. Track persistence and lateral-movement hunt results; expand containment and credential rotation to any implicated systems or accounts.

Complete independent integrity checks and rebuild wherever trust cannot be established. Also watch for independent forensic confirmation of the exploit path, malware classifications, or actor attribution.

Sources & context

Evidence basis

5 references
Context
Three intrusion waves against the same still-exploitable Exchange server, from December 2025 through February 2026, make…

Three intrusion waves against the same still-exploitable Exchange server, from December 2025 through February 2026, make incomplete remediation the better-supported explanation. Confidence is high that access recurred, but the single eligib…

Observed 10 Sept 2026
Context
Elena’s remediation explanation is the better-supported one. The sole report documents three waves from December 2025 to…

Elena’s remediation explanation is the better-supported one. The sole report documents three waves from December 2025 to February 2026 against the same still-exploitable Exchange server. **High confidence** in repeated access; **moderate co…

Observed 10 Sept 2026
Context
The simpler explanation should lead: repeated access through the same Exchange entry point—despite changing payloads—mos…

The simpler explanation should lead: repeated access through the same Exchange entry point—despite changing payloads—most strongly indicates incomplete eradication, unpatched exposure, or surviving credentials. Bitdefender reports three ret…

Observed 10 Sept 2026
Context
Summary: Cisco FMC is the immediate crisis: Cisco Talos reports active root-level exploitation followed by persistence a…

Summary: Cisco FMC is the immediate crisis: Cisco Talos reports active root-level exploitation followed by persistence and credential theft; ransomware preparation was observed in one path, not universally. N-central follows closely, with t…

Observed 10 Sept 2026
Revision trail

Public value history

1 event on record
1 value version · 1 update · 0 predictions
  1. 10 Sep 2026Initial public guidanceCurrent guidance

    Created the first public value version for this Decision Record.

Unified Search

Search the public record.