CVE-2021-26855criticalKEVEXPLOITRANSOMWARESECURIN PRIORITIZEDSecurin Validate-ReadyZero Day
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Vulnerability Type
SSRF (Server-Side Request Forgery)
Impact Type
Code Execution
Vector
NETWORK
Affected Vendors
microsoft
Securin Risk Score
CVSS: 9.8
Vulnerability Timeline
- 📋CVE Published
- 💥1st Exploit Published
- 🛡️Securin KEV Published
- 📄NVD Published
- 🔮Securin Predicted
- 🏛️CISA KEV Published
- ←Securin Predicted → NVD Latency: 1 day→
- ←Securin Predicted → CISA Latency: 243 days→
- ←Securin Predicted → Exploit Latency: 4 days→
Threat Intelligence Summary
Microsoft Exchange Server Remote Code Execution Vulnerability
Weaknesses
—
Threats
118
Threat Actor Associations
—
References
CVE
- https://ccb.belgium.be/advisories/multiple-critical-vulnerabilities-microsoft-exchange
- https://cert.europa.eu/publications/security-advisories/2021-013/
- https://www.hkcert.org/security-bulletin/microsoft-monthly-security-update-march-2021-_20210310
- https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES02&VLCODE=CIAD-2021-0012
- https://www.jpcert.or.jp/english/at/2021/at210012.txt
- https://www.zero-day.cz/database/612/
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-13639
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26855
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-26855.yaml
- https://proxylogon.com/
- https://nvd.nist.gov/vuln/detail/CVE-2021-26855
- http://packetstormsecurity.com/files/161846/Microsoft-Exchange-2019-SSRF-Arbitrary-File-Write.html
- http://packetstormsecurity.com/files/161938/Microsoft-Exchange-ProxyLogon-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/162610/Microsoft-Exchange-2019-Unauthenticated-Email-Download.html
- http://packetstormsecurity.com/files/162736/Microsoft-Exchange-ProxyLogon-Collector.html
- https://gist.github.com/testanull/324546bffab2fe4916d0f9d1f03ffa09
- https://googleprojectzero.github.io/0days-in-the-wild/0day-RCAs/2021/CVE-2021-26855.html
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26855
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26855
- https://proxylogon.com/#timeline
- https://thehackernews.com/2021/08/hackers-actively-searching-for.html
- https://web.archive.org/web/20210306113850/https://raw.githubusercontent.com/microsoft/CSS-Exchange/main/Security/http-vuln-cve2021-26855.nse
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26855
- https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
Exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://otx.alienvault.com/indicator/cve/CVE-2021-26855
- https://www.hivepro.com/russian-svr-exploits-another-set-of-publicly-known-vulnerabilities/
- https://duo.com/decipher/fbi-avoslocker-ransomware-hitting-u-s-critical-infrastructure
- https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/monitoring/?category=monitoring&statistic=unique_ips&d1=2026-08-12&d2=2026-08-12
- https://cxsecurity.com/issue/WLB-2021030171
- https://cxsecurity.com/issue/WLB-2021050123
- https://www.coresecurity.com/core-labs/exploits?exploit_name=Microsoft Exchange Proxylogon Remote Code Execution Vulnerability Exploit
- https://www.exploit-db.com/exploits/49637
- https://www.exploit-db.com/exploits/49663
- https://www.exploit-db.com/exploits/49879
- https://www.exploit-db.com/exploits/49895
- https://github.com/1342486672/Flangvik
- https://github.com/DCScoder/Exchange_IOC_Hunter
- https://github.com/Flangvik/SharpProxyLogon
- https://github.com/Immersive-Labs-Sec/ProxyLogon
- https://github.com/KotSec/CVE-2021-26855-Scanner
- https://github.com/La3B0z/CVE-2021-26855-SSRF-Exchange
- https://github.com/Mr-xn/CVE-2021-26855-d
- https://github.com/Nick-Yin12/106362522
- https://github.com/RickGeex/ProxyLogon
- https://github.com/SCS-Labs/HAFNIUM-Microsoft-Exchange-0day
- https://github.com/ShyTangerine/cve-2021-26855
- https://github.com/SimoesCTT/CTT-Exchange-RCE-v1.0---Microsoft-Exchange-Exploit-CVSS-10.0-CRITICAL-CVE-2021-26855-CVE-2021-27065
- https://github.com/SimoesCTT/CTT-ProxyLogon-RCE-v1.0---Convergent-Time-Theory-Enhanced-Microsoft-Exchange-Exploit
- https://github.com/TaroballzChen/ProxyLogon-CVE-2021-26855-metasploit
- https://github.com/Wercd/CVE-2021-26855
- https://github.com/Yt1g3r/CVE-2021-26855_SSRF
- https://github.com/ZephrFish/Exch-CVE-2021-26855
- https://github.com/ZephrFish/Exch-CVE-2021-26855_Priv
- https://github.com/alt3kx/CVE-2021-26855_PoC
- https://github.com/antichown/Scan-Vuln-CVE-2021-26855
- https://github.com/byinarie/Zirconium
- https://github.com/catmandx/CVE-2021-26855-Exchange-RCE
- https://github.com/cert-lv/exchange_webshell_detection
- https://github.com/conjojo/Microsoft_Exchange_Server_SSRF_CVE-2021-26855
- https://github.com/dwisiswant0/proxylogscan
- https://github.com/evilashz/ExchangeSSRFtoRCEExploit
- https://github.com/glen-pearson/ProxyLogon-CVE-2021-26855
- https://github.com/h4x0r-dz/CVE-2021-26855
- https://github.com/hackerschoice/CVE-2021-26855
- https://github.com/hackerxj007/CVE-2021-26855
- https://github.com/hakivvi/proxylogon
- https://github.com/haotiku/CVE-2021-26855-exploit-Exchange
- https://github.com/hictf/CVE-2021-26855-CVE-2021-27065
- https://github.com/hosch3n/ProxyVulns
- https://github.com/kh4sh3i/ProxyLogon
- https://github.com/mauricelambert/ExchangeWeaknessTest
- https://github.com/mekhalleh/exchange_proxylogon
- https://github.com/mil1200/ProxyLogon-CVE-2021-26855
- https://github.com/p0wershe11/ProxyLogon
- https://github.com/praetorian-inc/proxylogon-exploit
- https://github.com/probablysecure/Triage-CVE-2021-26855-ProxyLogon---Microsoft-Exchange-
- https://github.com/pussycat0x/CVE-2021-26855-SSRF
- https://github.com/r0xDB/CVE-2021-26855
- https://github.com/sgnls/exchange-0days-202103
- https://github.com/soteria-security/HAFNIUM-IOC
- https://github.com/srvaccount/CVE-2021-26855-PoC
- https://github.com/ssrsec/Microsoft-Exchange-RCE
- https://github.com/sydneysamantha/Triage-CVE-2021-26855-ProxyLogon---Microsoft-Exchange-
- https://github.com/thau0x01/poc_proxylogon
- https://github.com/timb-machine-mirrors/testanull-CVE-2021-26855_read_poc.txt
- https://github.com/wysssadda/ExchangeSmash
- https://github.com/yaoxiaoangry3/Flangvik
- https://www.rapid7.com/db/modules/exploit/windows/http/exchange_proxylogon_rce
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:ASP/CVE-2021-27065&ThreatID=2147776820
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:ASP/CVE-2021-27065.B!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Python/CVE-2021-26855!dha&ThreatID=2147777271
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Script/CVE-2021-26855!v2
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Script/Exmann.A!dha&ThreatID=2147776263
- https://packetstormsecurity.com/files/161846/Microsoft-Exchange-2019-SSRF-Arbitrary-File-Write.html
- https://packetstormsecurity.com/files/161938/Microsoft-Exchange-ProxyLogon-Remote-Code-Execution.html
- https://packetstormsecurity.com/files/162610/Microsoft-Exchange-2019-Unauthenticated-Email-Download.html
- https://packetstormsecurity.com/files/162736/Microsoft-Exchange-ProxyLogon-Collector.html
- https://packetstormsecurity.com/files/181115/Microsoft-Exchange-ProxyLogon-Scanner.html
- https://www.praetorian.com/blog/reproducing-proxylogon-exploit/
- https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
Malware
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper!MSR
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper!MTB
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper!rfn&ThreatID=2147830572
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.AA!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.AY!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.AZ!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.D!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.DA
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.E!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.Ex!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.F
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.F!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.F!dha&ThreatID=2147776280
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.G
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:Win64/GoDropper.A&ThreatID=2147778611
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/Exmann.A&ThreatID=2147773895
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/Exmann.B&ThreatID=2147773896
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/IISExchgSpawnEMS.A&ThreatID=2147754368
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=HackTool:Script/CVE-2021-26855.A
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=HackTool:Script/CVE-2021-26855.G&ThreatID=2147776971
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=HackTool:Win32/CVE-2021-26855!rfn&ThreatID=2147927643
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=HackTool:Win32/CVE-2021-26855.G&ThreatID=2147776970
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.A&ThreatID=2147777717
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.B&ThreatID=2147777719
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.C&ThreatID=2147778209
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.D&ThreatID=2147778221
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.E&ThreatID=2147778476
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.F&ThreatID=2147778477
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.G&ThreatID=2147778478
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/Redearps.A&ThreatID=2147778205
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/IISExchgSpawnCMD.A&ThreatID=2147776639
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/LemonDuck.A&ThreatID=2147777720
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=TrojanDownloader:Linux/LemonDuck.G!MSR&ThreatID=2147765978
- https://bitdefender.com/en-us/blog/hotforsecurity/ransomware-negotiator-working-other-side
- https://cloud.google.com/blog/topics/threat-intelligence/europe-data-leak-landscape
- https://cyberpress.org/florida-ransomware-negotiator-sentenced-blackcat-attacks/
- https://cyberpress.org/ransomware-shifts-to-data-theft/
- https://cybersecuritynews.com/hackers-weaponize-legitimate-windows-tools/
- https://securityaffairs.com/191100/security/ransomware-negotiator-caught-secretly-assisting-blackcat-extortion-scheme.html
- https://www.bleepingcomputer.com/news/security/former-ransomware-negotiator-pleads-guilty-to-blackcat-attacks/
- https://www.bleepingcomputer.com/news/security/us-charges-another-ransomware-negotiator-linked-to-blackcat-attacks/
- https://www.malwarebytes.com/blog/news/2026/07/the-inside-job-that-cost-ransomware-victims-millions
- https://www.ransomware.live/group/alphv
- https://www.varonis.com/blog/alphv-blackcat-ransomware
- https://blog.eclecticiq.com/the-analyst-prompt-39-ransomware-falsified-covid-certificates-us-blacklists-nso-group
- https://cyberpress.org/fortinet-flaws-fuel-ransomware/
- https://cybersecuritynews.com/conti-ransomware-hacker-sentenced/
- https://securityaffairs.com/195117/cyber-crime/ransomware-never-stopped-over-9000-confirmed-attacks-since-2018.html
- https://securityaffairs.com/198931/cyber-crime/conti-hacker-who-built-malware-and-attacked-victims-gets-four-year-sentence.html
- https://securityonline.info/conti-ransomware-guilty-plea/
- https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-pleads-guilty-in-the-us-faces-15-years-in-prison/
- https://www.pcrisk.com/removal-guides/17011-conti-ransomware
- https://www.ransomware.live/group/conti
- https://blog.qualys.com/vulnerabilities-threat-research/2022/03/06/avoslocker-ransomware-behavior-examined-on-windows-linux
- https://www.ransomware.live/group/avoslocker
- https://cybersecuritynews.com/ransomware-operators-disable-edr/
- https://www.bleepingcomputer.com/news/security/black-kingdom-ransomware-hacks-networks-with-pulse-vpn-flaws/
- https://redcanary.com/blog/blackbyte-ransomware/
- https://www.ransomware.live/group/blackbyte
- https://digital.nhs.uk/cyber-alerts/2021/cc-3874
- https://stairwell.com/resources/kuiper-ransomware-analysis-stairwells-technical-report/
- https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html
- https://thehackernews.com/2026/09/three-threat-groups-target-russian.html
- https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-cuba-ransomware/
- https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-flaws-exposing-backup-servers-to-rce-attacks/
- https://www.ransomware.live/group/cuba
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Ransom:Win32/DoejoCrypt.A&ThreatID=2147777392
Fix
- https://exchange.xforce.ibmcloud.com/vulnerabilities/197219
- https://www.tenable.com/plugins/nessus/147003
- https://www.tenable.com/plugins/nessus/147171
- https://msrc.microsoft.com/update-guide/vulnerability
- https://techcommunity.microsoft.com/t5/exchange-team-blog/released-march-2021-exchange-server-security-updates/ba-p/2175901
- https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server/
Unlock the details for this CVE
Sign up with Securin to access the full AI summary, impacted products, exploitability details, threat intelligence, discussions and reference mappings for this CVE.
Unlock with Securin