CVE-2021-26855Active Exploitation(microsoft / exchange_server)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft exchange_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Exchange Server Remote Code Execution Vulnerability

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-918

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_server

Threat summary

  • Active exploitation appears in 9 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 12 observed days

What's happening

  • Active exploitation reported across 9 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • General: 4 classified signals
  • Peaked 3d ago at 3 mentions (2026-09-02); latest day: 1
  • 14 total mentions across 12 days

Affected systems

Vendors
Products
exchange_server

3 versions affected across 1 product

Deep dive

Activity timeline14 mentions / 12d
01223Mentions · 2026-03-04: 1Mentions · 2026-03-11: 1Mentions · 2026-05-01: 1Mentions · 2026-05-02: 1Mentions · 2026-05-08: 1Mentions · 2026-05-15: 1Mentions · 2026-06-25: 1Mentions · 2026-06-27: 1Mentions · 2026-09-02: 3Mentions · 2026-09-15: 1Mentions · 2026-09-16: 1Mentions · 2026-09-18: 1PoC Mentioned / Linked · 2026-05-08: 1Exploit Tool / Code · 2026-06-25: 1Exploit Tool / Code · 2026-09-16: 1Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-02: 1Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-06-27: 1Active Exploitation · 2026-09-15: 1Active Exploitation · 2026-09-16: 1Active Exploitation · 2026-09-18: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-02: 1Technical Details · 2026-06-27: 1Technical Details · 2026-09-16: 1Technical Details · 2026-09-18: 103-0403-1105-0105-0205-0805-1506-2506-2709-0209-1509-1609-18
Signal classification3 categories
Active Exploitation
964.3%
General
428.6%
PoC
17.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-041
Active Exploitation1
2026-03-111
Active Exploitation1
2026-05-011
Active Exploitation1
2026-05-021
Active Exploitation1
2026-05-081
PoC1
2026-05-151
General1
2026-06-251
Active Exploitation1
2026-06-271
Active Exploitation1
2026-09-023
General3
2026-09-151
Active Exploitation1
2026-09-161
Active Exploitation1
2026-09-181
Active Exploitation1
Full discourse14 posts
  • ThreatCluster@threatcluster
    Active Exploitation

    Hacking Cat is exploiting Microsoft Exchange CVE-2021-26855 and CVE-2026-42897 to deploy Gorilla RAT and tunnel into Russian internal networks. https://threatcluster.io/cluster/pro-ukraine-hacking-cat-group-unleashes-new-malware-against--112cc02c?utm_source=twitter&utm_medium=social&utm_campaign=social_agent

    Post summary

    The tweet reports that the hacking group Hacking Cat is actively exploiting CVE-2021-26855 and CVE-2026-42897 to install Gorilla RAT and tunnel into Russian internal networks.

    04191499
    561 followersView on X
  • connect24h@connect24h
    Active Exploitation

    SharkLoaderは「侵入後にCobalt Strike」までの段取りがかなり生々しい。StrikeSharkはProxyLogon、Openfire、GeoServerなど既知CVEを入口に、SystemSettings.exeのDLL side-loadingでBeaconを起こす。 Kaspersky観測ではインドネシア外交組織、台湾政府系、各国のソフトウェア開発企業まで対象。調べてみると、これはゼロデイ騒ぎより“未修正の公開系サーバが足場化する”話っぽい。CVE-2021-26855、CVE-2023-32315、CVE-2024-36401の露出、web shell、Run key、scheduled task、SystemSettings.dll、DscCoreR.mui、LSASS/NTDSアクセスのチェックを。 #セキュリティ https://thehackernews.com/2026/06/new-sharkloader-malware-deploys-cobalt.html

    Post summary

    SharkLoader leverages several known CVEs (including ProxyLogon, Openfire, GeoServer) to gain initial access and deploy Cobalt Strike, with Kaspersky reporting active attacks on government and software‑development targets across multiple regions.

    00010216
    4.0K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    The StrikeShark campaign uses SharkLoader malware to deploy Cobalt Strike Beacons by exploiting CVE-2021-26855 in Microsoft Exchange and CVE-2023-32315 in Openfire, targeting diplomatic and government sectors across Indonesia, Taiwan, and Colombia, Securelist reported. https://t.co/QXSAnBDQuB

    Post summary

    StrikeShark actively exploits CVE-2021-26855 in Microsoft Exchange and CVE-2023-32315 in Openfire using SharkLoader and Cobalt Strike, targeting diplomatic and government sectors in Indonesia, Taiwan, and Colombia.

    10000143
    395 followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The text lists a number of Windows CVE identifiers without providing any additional detail or context.

    10000106
    15 followersView on X
  • David@davidsheyi
    Active Exploitation

    1/ China: APT41 is notorious for espionage. They leverage CVE-2021-26855 to exploit Exchange Servers. Stay patched and monitor network traffic. #NationState #InfoSec

    Post summary

    APT41 is actively exploiting CVE‑2021‑26855 against Exchange servers, so users should apply patches and monitor traffic.

    1000016
    557 followersView on X
  • David@davidsheyi
    Active Exploitation

    1/ Meet APT41: Known for exploiting CVE-2021-26855 in the Microsoft Exchange hack. They target healthcare & telecom sectors. #ThreatIntel #InfoSec

    Post summary

    APT41 is actively exploiting CVE-2021-26855 in Microsoft Exchange attacks, targeting the healthcare and telecom sectors.

    1000061
    556 followersView on X
  • BT Haberler@BTHaberler
    Active Exploitation

    Kaspersky, Rus İşletmelerini Hedef Alan Üç Ayrı Siber Casusluk Grubunu Ortaya Çıkardı! Kaspersky, Rus kuruluşlarına karşı eş zamanlı faaliyet gösteren üç farklı tehdit grubunu tespit etti: "NightEagle" grubu, GhostContainer adlı modüler arka kapı ve BlueKeep (CVE-2019-0708) açığıyla Microsoft Exchange sunucularına sızarken, "Hacking Cat" grubu Exchange açığı CVE-2021-26855 üzerinden Gorilla RAT ve Monkey fidye yazılımını dağıtıyor, "Toy Ghouls" grubu ise MQTT ve Element Messenger üzerinden komuta kontrol kuran "Bird Agent" arka kapısını kullanıyor. • NightEagle'ın VPN bağlantılarının Rus ağ segmentindeki IP adreslerinden geldiği, ayrıca DCSync saldırılarıyla yetki yükseltmesi yaptığı tespit edildi. • Üç grubun da farklı araç ve teknikler kullanması, Rus kuruluşlarının aynı anda birden fazla bağımsız tehdit aktörünün hedefinde olduğunu gösteriyor. Üç farklı casusluk ve fidye yazılımı grubunun aynı ülkedeki kuruluşları eş zamanlı ama birbirinden bağımsız biçimde hedef alması, büyük ve stratejik önemi yüksek ekonomilerin sürekli olarak çok cepheli siber tehdit baskısı altında kaldığını gösteriyor. #SiberGüvenlik #APT #FidyeYazılımı

    Post summary

    Kaspersky disclosed three APT groups actively exploiting CVE-2019-0708 and CVE-2021-26855 against Russian organizations, deploying backdoors like GhostContainer and Bird Agent alongside RATs such as Gorilla RAT and Monkey malware.

    0000042
    44 followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    NightEagle operators hit Exchange via CVE-2020-0688 to plant GhostContainer. They pull the http://ASP.NET machine keys, then overwrite VIEWSTATE so the server deserializes attacker-controlled data and executes payloads straight from memory. GhostWebShell plus Neo-reGeorg handle persistence while Microsoft dev tunnels and rdp2tcp move traffic laterally; CVE-2019-0708 and DCSync round out the chain. Hacking Cat started in Feb 2024 abusing CVE-2021-26855 to drop the Go-based Gorilla RAT. From there they push Monkey ransomware builds in Rust, .NET, C++, or Go. The Rust samples use ChaCha20-Poly1305; the .NET ones stick to AES-256-CBC. Artifacts first appeared late summer 2025. Toy Ghouls has run mqtt-bird-agent and matrix-bird-agent since mid-2026. Both register as Windows services, seed their keys from MachineGuid, and beacon over HiveMQ MQTT or Element Matrix after Evil-WinRM entry. Track the distinct TTP sets on the same Exchange hosts before you merge the incidents.

    Post summary

    The report details multiple threat actor groups actively exploiting CVEs (CVE-2020-0688, CVE-2019-0708, CVE-2021-26855) to deploy malware, maintain persistence, and move laterally, citing specific tools and techniques but no patches or mitigations.

    00000100
    172 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2021-26855 — Microsoft Corporation Visit -- https://cti.loginsoft.com/ip/20.172.67.176 #Loginsoft #Cytellite #Cybersecurity #CVE202126855 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/t0z0nJrfA2

    Post summary

    The tweet announces a recent detection of CVE-2021-26855 by Cytellite, providing a link to a detection page but no further technical or exploit details.

    0000025
    23 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2021-26855 — Microsoft Corporation Visit -- https://cti.loginsoft.com/ip/20.172.67.176 #Loginsoft #Cytellite #Cybersecurity #CVE202126855 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/jZwXNXYmWa

    Post summary

    The tweet reports a recent detection of CVE‑2021‑26855 by Cytellite, but provides no technical, PoC, exploit, or patch details.

    0000024
    23 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2021-26855 — Microsoft Corporation Visit -- https://cti.loginsoft.com/ip/20.172.67.176 #Loginsoft #Cytellite #Cybersecurity #CVE202126855 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/yAgb90Vd64

    Post summary

    Cytellite alerts to detection activity around CVE‑2021‑26855, but provides no deeper technical, exploit, or mitigation information.

    0000025
    23 followersView on X
  • Paul Fregonese@paul_fregonese
    PoC

    ProxyLogon (CVE-2021-26855) had a public PoC before most Exchange admins finished their morning coffee. Median patch time: 57 days. Average dwell: longer. The vuln was the headline. The unpatched estate was the actual story. https://t.co/HZ0vq6k0l2

    Post summary

    The tweet emphasizes that a public Proof of Concept existed for ProxyLogon (CVE‑2021‑26855) while many Exchange administrators were still unpatched, underscoring the delayed response to the vulnerability.

    0000031
    45 followersView on X
  • Echelongraph Team@echelongraph
    Active Exploitation

    4 threat groups. Shared C2 infrastructure. 8 countries compromised. This campaign by SHADOW-EARTH-053 is a masterclass in why attack surface visibility matters: ⚠️ Internet-facing Exchange servers — unpatched ProxyLogon (CVE-2021-26855) ⚠️ IIS web servers with known N-day flaws ⚠️ Credential harvesting via 1x1 tracking pixels & OAuth token theft ⚠️ Lateral movement via ShadowPad + DLL sideloading What caught our eye: The attack graph shows CL-STA-0049, REF7707, Earth Alux, and SHADOW-EARTH-054 all sharing VARGEIT (Squidoor/FinalDraft) infrastructure → converging on 209.141.40.254 → http://zimbra-beta.info. This is not 4 separate problems. This is 1 attack surface with 4 entry points. At @EchelonGraph, we built our platform to map exactly these relationships: 🔹 Surface Scanner — discover exposed Exchange/IIS endpoints before attackers do 🔹 Attack Graph — visualize infrastructure overlaps across threat groups 🔹 Shadow AI Radar — detect unauthorized services running on your perimeter 🔹 CVE Correlation — flag ProxyLogon-vulnerable assets automatically If your org runs internet-facing Exchange or IIS — you need visibility today, not after the next advisory. https://echelongraph.io @citizenlab @TheHackersNews #CyberSecurity #APT #ThreatIntelligence #AttackSurface #ProxyLogon #ShadowPad #InfoSec #MITRE #CVE #IncidentResponse #SecOps #ChinaAPT #NationStateThreats #ExchangeServer #PatchManagement

    Post summary

    The post describes a multi‑group campaign exploiting the unpatched ProxyLogon vulnerability on Exchange servers, underscoring current active attacks and emphasizing the need for visibility before patching.

    0000047
    2 followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Active Exploitation

    'Exchange/IIS flaws' = the ProxyLogon chain (CVE-2021-26855 + friends). 2021 CVEs still finding unpatched servers in 2026. ShadowPad gets sideloaded off a signed binary; Godzilla webshell holds the door open. The patch is five years old.

    Post summary

    The text highlights that the ProxyLogon chain remains actively exploited, noting unpatched servers in 2026 and that the related patch is five years old.

    0000046
    34 followersView on X
CPE platform detail24 entries

24 of 24 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_server2013--
Appmicrosoftexchange_server2013--
Appmicrosoftexchange_server2013--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--

Explore more