CVE-2021-28481Disclosure(microsoft / exchange_server)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Microsoft Exchange Server Remote Code Execution Vulnerability

1.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_server

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-17); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
exchange_server

3 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-17: 1Mentions · 2026-03-17: 1PoC Mentioned / Linked · 2026-02-17: 1Technical Details · 2026-02-17: 102-1703-17
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-171
Disclosure1
2026-03-171
General1
Full discourse2 posts
  • ET Labs@ET_Labs
    General

    35 new OPEN, 66 new PRO (35 + 31) ACR Stealer, Katana Botnet, Lumma Stealer, NetSupport RAT, TA4903, TA569, XWorm, FreePBX (CVE-2026-28287), Linksys (CVE-2025-34037), Microsoft Exchange (CVE-2021-28480, CVE-2021-28481), Nginx-ui (CVE-2026-27944) and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-03-17-v11150/3235 https://t.co/SNltFetetX

    Post summary

    The tweet lists several new CVEs and links to a rule‑set update, but provides no depth on exploitation, mitigation, or technical details.

    03050465
    5.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2021-28481 - critical 🚨 Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound) > Microsoft Exchange Server contains a remote code execution caused by improper input v... 👾 https://cloud.projectdiscovery.io/library/CVE-2021-28481 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2021-28481 is a critical Microsoft Exchange flaw enabling pre‑authentication SSRF/ACL bypass leading to remote code execution, with a link provided to a Project Discovery library entry for more information.

    00000195
    888 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_server2013--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--

Explore more