Decision RecordActivePublished without chair review
CRT-2026-026810 Sep 2026MORNING EDITIONDaily Roundtable
Recovery of Exchange servers with recurring unauthorized access
Isolate and preserve affected servers, fully patch the Exchange estate, rotate privileged and service credentials, revoke sessions, hunt enterprise-wide, and rebuild any server whose integrity cannot be independently established.
Current public guidance · the full record
What to do now
Under reviewAt a glance- NewTreat repeatedly exposed ProxyNotShell-affected Exchange servers as potentially incompletely recovered; isolate, preserve evidence, rotate credentials, and rebuild when integrity is uncertain. —
Why now
Under reviewAs assessed on September 10, 2026, the packet describes three returns to the same still-exploitable Exchange server between December 2025 and February 2026.
That recurrence makes a one-time containment response insufficient: patching, access revocation, enterprise hunting, and integrity verification must be completed before the environment can be trusted.
The urgency rests on repeated unauthorized access, not on proof that CVE-2022-41040 and CVE-2022-41082 were freshly exploited in every wave.
Who is affected
Under reviewThe directly affected deployment is the repeatedly accessed Exchange server at an unnamed Azerbaijani oil-and-gas organization, reported as still exploitable during three waves from December 2025 through February 2026.
Its operators face an unresolved server-integrity question. Administrators of the wider Exchange estate must verify patching for CVE-2022-41040 and CVE-2022-41082 because the packet supplies no server versions or estate-wide patch inventory.
Privileged and service accounts exposed to the server, and users with active sessions, face possible continued access through surviving credentials or sessions.
Enterprise systems reachable from the Exchange environment require hunting for persistence and lateral movement, although neither is confirmed across the estate.
What supports this
SupportedSupport — The intelligence analyst’s account says the sole report documented three intrusion waves from December 2025 through February 2026 against the same still-exploitable Exchange server, supporting the finding of recurring access.
Support — The geopolitical analysis says repeated use of the same Exchange entry point despite changing payloads most strongly indicates incomplete eradication, unpatched exposure, or surviving credentials.
Support with qualification — The moderator found recurring access highly credible but said the report could not determine whether each wave was fresh exploitation or continued access.
Evidence gap — The evidence audit found the isolation, preservation, patching, credential rotation, session revocation, hunting, and conditional rebuilding actions consistently supported, while finding no independent confirmation that CVE-2022-41040 and CVE-2022-41082 caused every wave.
How the Roundtable reached this
Under reviewThe geopolitical contributor identified incomplete eradication, unpatched exposure, or surviving credentials as better-supported explanations than state signaling because access repeatedly used the same Exchange entry point despite changing payloads.
The intelligence analyst agreed, citing three waves from December 2025 through February 2026 against the same still-exploitable Exchange server, while rating the CVE-2022-41040 and CVE-2022-41082 path only moderate confidence.
The moderator resolved the issue by separating the high-confidence finding of recurring access from the unproven cause. The evidence audit supported comprehensive recovery but identified an evidence gap around fresh exploitation; the boundary review therefore required qualified vulnerability linkage.
No existing Decision Record was found, and the arbiter selected a new operational recovery decision.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 5 candidate signals.
- Linker (AI panel role)Linker evaluated 5 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 13 evidence signals; 8 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 0 predictions and rejected 2 claims.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 10 public/private findings.
- Arbiter (AI panel role)Arbiter produced 5 decision envelopes.
Key disagreement
Scout (AI panel role)
The evidence comes from one eligible report and does not establish whether each wave was fresh exploitation or continued access. The exact exploit path, malware classification, and actor attribution have varying confidence.
Arbiter outcome
Arbiter outcome: new decision record. The evidence supports a new operational recovery decision, no existing record was linked, and the attribution and exploit-path uncertainty can be handled through qualified public wording.
Candidates considered
Considered 5 candidates · opened 1 · 4 not opened (4 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingOne eligible incident report underlies the account.
Recurring access is supported with high confidence, but the report cannot establish whether every wave was fresh exploitation or continued access through persistence, incomplete eradication, or surviving credentials.
The CVE-2022-41040 and CVE-2022-41082 path is inferred from w3wp.exe and Exchange PowerShell process activity rather than independently confirmed. Deed RAT is directly reported; TernDoor is only a possible classification based on behavioral and code similarities.
Actor attribution also lacks independent corroboration.
What evidence is missing
MissingThe packet lacks independent forensic confirmation that CVE-2022-41040 and CVE-2022-41082 caused each wave.
It does not provide Exchange version numbers, estate-wide patch levels, authoritative affected or fixed versions, or evidence showing why the server remained exploitable.
It also lacks artifacts that distinguish fresh exploitation from persistence or surviving credentials, independent confirmation of the possible TernDoor identification, and corroboration of the alleged China-linked attribution.
What would change this
Under reviewThe recovery posture could narrow if verified patching for CVE-2022-41040 and CVE-2022-41082, credential rotation, session revocation, enterprise hunting, and independent integrity checks establish a trustworthy state with no renewed activity.
Conversely, renewed access, discovered persistence or lateral movement, or an inability to establish integrity triggers rebuilding and broader containment.
Direct forensic proof that each wave exploited CVE-2022-41040 and CVE-2022-41082 would strengthen the causal finding but would not reduce the recovery actions.
What to watch next
Under reviewVerify patch completion for CVE-2022-41040 and CVE-2022-41082 on every Exchange server.
After credential rotation and session revocation, monitor for renewed unauthorized access; isolate and rebuild the server if it recurs. Track persistence and lateral-movement hunt results; expand containment and credential rotation to any implicated systems or accounts.
Complete independent integrity checks and rebuild wherever trust cannot be established. Also watch for independent forensic confirmation of the exploit path, malware classifications, or actor attribution.
Evidence basis
Three intrusion waves against the same still-exploitable Exchange server, from December 2025 through February 2026, make incomplete remediation the better-supported explanation. Confidence is high that access recurred, but the single eligib…
Elena’s remediation explanation is the better-supported one. The sole report documents three waves from December 2025 to February 2026 against the same still-exploitable Exchange server. **High confidence** in repeated access; **moderate co…
The simpler explanation should lead: repeated access through the same Exchange entry point—despite changing payloads—most strongly indicates incomplete eradication, unpatched exposure, or surviving credentials. Bitdefender reports three ret…
Summary: Cisco FMC is the immediate crisis: Cisco Talos reports active root-level exploitation followed by persistence and credential theft; ransomware preparation was observed in one path, not universally. N-central follows closely, with t…
Public value history
- 10 Sep 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableMorning roundtableConvened 10 Sep 2026Methodology
How the panel reaches a Public Decision Record.