CVE-2021-31207Active Exploitation(microsoft / exchange_server)

HIGHCVSS 6.6 · MEDIUMCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft exchange_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Exchange Server Security Feature Bypass Vulnerability

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-434

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-19); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
exchange_server

3 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-19: 1Mentions · 2026-05-15: 1Mentions · 2026-06-15: 1Exploit Tool / Code · 2026-06-15: 1Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-06-15: 1Patch / Workaround · 2026-03-19: 103-1905-1506-15
Signal classification2 categories
Active Exploitation
266.7%
General
133.3%
Classification over time
DateTotalLabels
2026-03-191
Active Exploitation1
2026-05-151
General1
2026-06-151
Active Exploitation1
Full discourse3 posts
  • Alice Sn0w •ᴗ•@Sn0wAlice
    Active Exploitation

    4/ Leur arsenal ressemble à un manuel de red team : • Carbanak • Cobalt Strike • Mimikatz • Lizar (leur loader maison) Initial access via Zerologon (CVE-2020-1472) et ProxyShell (CVE-2021-31207).

    Post summary

    Threat actors are actively exploiting Zerologon and ProxyShell using standard red‑team tools such as Cobalt Strike and Mimikatz, indicating ongoing real‑world attacks.

    10010107
    1.6K followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The content is simply a list of Windows CVE identifiers with no additional context, exploitation evidence, or remediation information.

    10000106
    15 followersView on X
  • David@davidsheyi
    Active Exploitation

    1/ ProxyShell comprises CVE-2021-34473, CVE-2021-34523 & CVE-2021-31207. Despite patches, unpatched systems are exploited for initial access. #Microsoft #Exchange

    Post summary

    The message reports that ProxyShell—comprising CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207—is actively exploited for initial access on unpatched Microsoft Exchange systems.

    1000030
    555 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_server2013--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--

Explore more