Microsoft Exchange Server Remote Code Execution Vulnerability
Published: 2021-03-03
Four zero-day vulnerabilities in Microsoft Exchange servers have been used in chained attacks in the wild.
https://thehackernews.com/2026/09/three-threat-groups-target-russian.html
https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html
https://thehackernews.com/2026/06/new-sharkloader-malware-deploys-cobalt.html
https://securelist.com/strikeshark-campaign/120326/
https://www.sophos.com/en-us/blog/initial-access-techniques-used-by-iran-based-threat-actors
https://thehackernews.com/2025/06/hackers-target-65-microsoft-exchange.html
https://thehackernews.com/2025/03/kaspersky-links-head-mare-to-twelve.html
https://securelist.com/head-mare-twelve-collaboration/115887/
https://www.microsoft.com/en-us/security/blog/2025/03/05/silk-typhoon-targeting-it-supply-chain/
https://www.darkreading.com/remote-workforce/china-silk-typhoon-it-supply-chain-attacks
https://thehackernews.com/2025/03/china-linked-silk-typhoon-expands-cyber.html
https://hackread.com/chinese-silk-typhoon-group-it-tools-network-breaches/
https://thehackernews.com/2025/01/new-eagerbee-variant-targets-isps-and.html
https://securelist.com/eagerbee-backdoor/115175/
https://www.theregister.com/2024/11/27/salt_typhoons_us_telcos/
https://thehackernews.com/2024/11/chinese-hackers-use-ghostspider-malware.html
https://www.trendmicro.com/en_us/research/24/k/earth-estries.html
https://www.darkreading.com/threat-intelligence/prometei-botnet-cryptojacker-worldwide
https://securelist.com/incident-response-interesting-cases-2023/113611/
https://unit42.paloaltonetworks.com/operation-diplomatic-specter/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-215a
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
https://www.tenable.com/cyber-exposure/a-look-inside-the-ransomware-ecosystem
https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-117a
https://www.tenable.com/cyber-exposure/2021-threat-landscape-retrospective
https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a
https://www.welivesecurity.com/2021/03/10/exchange-servers-under-siege-10-apt-groups/
https://msrc.microsoft.com/blog/2021/03/multiple-security-updates-released-for-exchange-server/
https://medium.com/@DCSO_CyTec/apt41-the-spy-who-failed-to-encrypt-me-24fc0f49cad1
https://www.tenable.com/blog/from-bugs-to-breaches-25-significant-cves-as-mitre-cve-turns-25
https://www.tenable.com/blog/microsofts-feb-2024-patch-tuesday-cve-2024-21351-cve-2024-21412
https://www.tenable.com/blog/aa23-215a-2022s-top-routinely-exploited-vulnerabilities
https://www.tenable.com/blog/microsoft-s-march-2021-patch-tuesday-addresses-82-cves-cve-2021-26411
https://github.com/enjoylife96962930-a11y/bug-bounty-series-2026
https://github.com/ushst/exchange-recon
https://github.com/panda12332145/cve-vulnerability-scanner
https://github.com/Hector-Abarca/realrisk-checks
https://github.com/akrishnash/anamoly_detection
https://github.com/fDarkShadow/noctis
https://github.com/saadabbasi-playground/detectionvalidation
https://github.com/Vekronrr/threat-intel-rag
https://github.com/sreer22/VulnScan-Pro-Web-Application-Vulnerability-Scanner
https://github.com/shaharyar0306/suricata-ips-autotuner
https://github.com/yashmoar11/RAG-poison
https://github.com/THU-HJY/CVE-Honeypot
https://github.com/hermestoola/bb-hunter-pro
https://github.com/lizuyi-6/aetherguard-security-dataset
https://github.com/tongchengbin/nvdlib
https://github.com/0wn2886/CVE-Web
https://github.com/b4nxzz/CVEs
https://github.com/mrhili/CVE-SEARCH-NVD
https://github.com/EvilGreys/CVE
https://github.com/ssrsec/Microsoft-Exchange-RCE
https://github.com/heikanet/Microsoft-Exchange-RCE
https://github.com/34zY/APT-Backpack
https://github.com/iitsmel/Research
https://github.com/kh4sh3i/ProxyLogon
https://github.com/TheDudeD6/ExchangeSmash
https://github.com/vehemont/nvdlib
https://github.com/cryptolakk/ProxyLogon-Mass-RCE
https://github.com/Nick-Yin12/106362522
https://github.com/hosch3n/ProxyVulns
https://github.com/praetorian-inc/proxylogon-exploit
https://github.com/p0wershe11/ProxyLogon
https://github.com/TaroballzChen/ProxyLogon-CVE-2021-26855-metasploit
https://github.com/Immersive-Labs-Sec/ProxyLogon
https://github.com/RickGeex/ProxyLogon
https://github.com/evilashz/ExchangeSSRFtoRCEExploit
https://github.com/ZephrFish/Exch-CVE-2021-26855
https://github.com/hakivvi/proxylogon
https://github.com/SCS-Labs/HAFNIUM-Microsoft-Exchange-0day
https://github.com/raheel0x01/CVE-2021-26855
https://github.com/srvaccount/CVE-2021-26855-PoC
https://github.com/DCScoder/Exchange_IOC_Hunter
https://github.com/mauricelambert/ExchangeWeaknessTest
https://github.com/dwisiswant0/proxylogscan
https://github.com/hackerxj007/CVE-2021-26855
https://github.com/charlottelatest/CVE-2021-26855
https://github.com/Yt1g3r/CVE-2021-26855_SSRF
https://github.com/mekhalleh/exchange_proxylogon
https://github.com/Th3eCrow/CVE-2021-26855-SSRF-Exchange
https://github.com/La3B0z/CVE-2021-26855-SSRF-Exchange
https://github.com/conjojo/Microsoft_Exchange_Server_SSRF_CVE-2021-26855
https://github.com/cert-lv/exchange_webshell_detection
https://github.com/soteria-security/HAFNIUM-IOC
https://github.com/sgnls/exchange-0days-202103
https://github.com/stressboi/hafnium-exchange-splunk-csvs
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26855
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26855
Published: 2021-03-03
Updated: 2026-08-19
Named Vulnerability: ProxylogonNamed Vulnerability: ProxyShellNamed Vulnerability: ProxyLogonKnown Exploited Vulnerability (KEV)
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99996