CVE-2021-26855: Microsoft Exchange Server Remote Code Execution
Microsoft Exchange Server Remote Code Execution Vulnerability. Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- CISA KEV-listed (remediation due 2022-05-03)
- used in ransomware campaigns
- EPSS 100.0% (100.0% percentile)
- CVSS 9.1 critical
Detection rules
- ProxyLogon Reset Virtual Directories Based On IIS Log critical
- ProxyLogon MSExchange OabVirtualDirectory critical
Related briefings
- 22,000 Exchange servers still exposed to a public exploit 2026-09-03
- New SharkLoader malware hits diplomats and governments with Cobalt Strike 2026-06-24
- HAFNIUM's ProxyLogon Chain Triggers 44,000 Exploitation Attempts from 1,600+ IPs Within Weeks of Disclosure 2026-02-16
Linked threat actors
- HAFNIUM machine-inferred link