CVE-2021-26855: Microsoft Exchange Server Remote Code Execution
Microsoft Exchange Server Remote Code Execution Vulnerability. Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- CISA KEV-listed (remediation due 2022-05-03)
- used in ransomware campaigns
- EPSS 100.0% (100.0% percentile)
- CVSS 9.1 critical
Detection rules
- ProxyLogon Reset Virtual Directories Based On IIS Log critical
- ProxyLogon MSExchange OabVirtualDirectory critical
Related briefings
- New SharkLoader malware hits diplomats and governments with Cobalt Strike 2026-06-24
- HAFNIUM's ProxyLogon Chain Triggers 44,000 Exploitation Attempts from 1,600+ IPs Within Weeks of Disclosure 2026-02-16