CVE-2021-34473Active Exploitation(microsoft / exchange_server)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft exchange_server systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Exchange Server Remote Code Execution Vulnerability

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Peaked 1d ago at 1 mentions (2026-03-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
exchange_server

3 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-11: 1Mentions · 2026-03-19: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-19: 1Patch / Workaround · 2026-03-19: 103-1103-19
Signal classification1 categories
Active Exploitation
2100.0%
Full discourse2 posts
  • David@davidsheyi
    Active Exploitation

    1/ ProxyShell comprises CVE-2021-34473, CVE-2021-34523 & CVE-2021-31207. Despite patches, unpatched systems are exploited for initial access. #Microsoft #Exchange

    Post summary

    ProxyShell, comprising CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207, continues to be actively exploited for initial access on unpatched Microsoft Exchange systems despite the availability of patches.

    1000030
    555 followersView on X
  • David@davidsheyi
    Active Exploitation

    5/ BlackCat's attack on the logistics firm Expeditors in 2022 showcased their ability to disrupt supply chains. They often exploit CVE-2021-34473 #ThreatIntel #InfoSec

    Post summary

    BlackCat reportedly exploits CVE-2021-34473 in attacks against Expeditors, showing active use of this vulnerability in the wild.

    1000044
    557 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_server2013--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--

Explore more