CVE-2021-26855

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 21 articles Published: 2021-03-02

EPSS Score

Source: FIRST.org · 2026-05-24
94.34%
probability
This CVE has a 94.34% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
9.1
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Temporal
Exploit Code Maturity
Functional
Remediation Level
Official Fix
Report Confidence
Confirmed
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:F/RL:O/RC:C

Description

Project Zero
Server-side request forgery (SSRF)

Affected Products

Microsoft
Microsoft Exchange Server 2016 Cumulative Update 19
15.01.0
Microsoft
Microsoft Exchange Server 2019 Cumulative Update 8
15.02.0
Microsoft
Microsoft Exchange Server 2019
15.02.0
Microsoft
Microsoft Exchange Server 2013 Cumulative Update 22
15.00.0
Microsoft
Microsoft Exchange Server 2019 Cumulative Update 2
15.02.0

Attack Intelligence

Google Project Zero

Patched
March 2, 2021
Reported by
Volexity, Orange Tsai from DEVCORE research team, and Microsoft Threat Intelligence Center (MSTIC)
Root Cause Analysis
https://googleprojectzero.github.io/0days-in-the-wild/0day-RCAs/2021/CVE-2021-26855.html

Exploits & PoC

hosch3n/ProxyVulns

[ProxyLogon] CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit. [ProxyOracle] CVE-2021-31195 & CVE-2021-31196 Exploit Chains. [ProxyShell]

178
dwisiswant0/proxylogscan

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as th

163
p0wershe11/ProxyLogon

ProxyLogon(CVE-2021-26855+CVE-2021-27065) Exchange Server RCE(SSRF->GetWebShell)

124
h4x0r-dz/CVE-2021-26855

PoC CVE-2021-26855 — h4x0r-dz/CVE-2021-26855

100
cert-lv/exchange_webshell_detection

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857, CVE-202

99
hackerschoice/CVE-2021-26855

PoC of proxylogon chain SSRF(CVE-2021-26855) to write file by testanull, censored by github

62
alt3kx/CVE-2021-26855_PoC

PoC CVE-2021-26855 — alt3kx/CVE-2021-26855_PoC

53
praetorian-inc/proxylogon-exploit

Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.

51
conjojo/Microsoft_Exchange_Server_SSRF_CVE-2021-26855

Microsoft Exchange Server SSRF漏洞(CVE-2021-26855)

36
9 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 94.34%
CVSS v3.1 9.1
Mentions 21
Last Seen May 27, 2026

CNA Information

CNA Assigner
microsoft
CNA Title
Microsoft Exchange Server Remote Code Execution Vulnerability

Analyst Note

CVE-2021-26855 is a critical RCE vulnerability in Microsoft Exchange Server with a CVSS score of 9.1, reported by Google Project Zero and documented in official security advisories (CERT-EU). The confirmed status is strongly supported by the zero-day classification from a trusted security research organization and immediate vendor attention.

Threat Actors 61

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Turla Group
apt_group Information theft and espionage Russian Federation
APT 29
apt_group Information theft and espionage 🇷🇺 RU
Mustang Panda
apt_group Information theft and espionage 🇨🇳 CN
WIZARD SPIDER
apt_group Financial gain 🇷🇺 RU
Cobalt
apt_group Financial crime 🇷🇺 RU
APT37
apt_group Information theft and espionage 🇰🇵 KP
APT 28
apt_group Information theft and espionage 🇷🇺 RU
FIN7
apt_group Financial crime 🇷🇺 RU
EMISSARY PANDA
apt_group Information theft and espionage 🇨🇳 CN
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Vicious Panda
apt_group Information theft and espionage 🇨🇳 CN
Careto
apt_group Information theft and espionage 🇪🇸 ES
GOLD CABIN
apt_group 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
GhostEmperor
apt_group Information theft and espionage 🇨🇳 CN
SCATTERED SPIDER
apt_group Financial crime 🇺🇸 US
Watchdog
apt_group 🇨🇳 CN
Ice Fog
apt_group Information theft and espionage 🇨🇳 CN
Tick
apt_group Information theft and espionage 🇨🇳 CN
APT3
apt_group Information theft and espionage 🇨🇳 CN
Infy
apt_group Information theft and espionage 🇮🇷 IR
Naikon
apt_group Information theft and espionage 🇨🇳 CN
GCHQ
apt_group Information theft and espionage 🇬🇧 GB
TA428
apt_group Information theft and espionage 🇨🇳 CN
Silence group
apt_group Financial crime 🇷🇺 RU
APT42
apt_group Information theft and espionage 🇮🇷 IR
Tortoiseshell
apt_group Information theft and espionage 🇮🇷 IR
[Unnamed group]
apt_group 🇨🇳 CN
Fox Kitten
apt_group Information theft and espionage 🇮🇷 IR
Attor
apt_group 🇷🇺 RU
PhantomCore
apt_group 🇷🇺 RU
Returned Libra
apt_group 🇨🇳 CN
Head Mare
apt_group 🇺🇦 UA
Earth Baxia
apt_group Information theft and espionage 🇨🇳 CN
CoughingDown
apt_group 🇨🇳 CN
Flax Typhoon
apt_group Information theft and espionage 🇨🇳 CN
Operation Cobalt Whisper
apt_group Financial crime 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Tonto Team
apt_group Information theft and espionage 🇨🇳 CN
PKPLUG
apt_group Information theft and espionage 🇨🇳 CN
Mikroceen
apt_group Information theft and espionage 🇨🇳 CN
Red October
apt_group 🇷🇺 RU
Night Dragon
apt_group Information theft and espionage 🇨🇳 CN
The White Company
apt_group Information theft and espionage 🇨🇳 CN
Pat Bear
apt_group 🇸🇾 SY
Calypso
apt_group Information theft and espionage 🇨🇳 CN
ExCobalt
apt_group 🇷🇺 RU
Unnamed Actor
apt_group 🇨🇳 CN
TA2552
apt_group Information theft and espionage 🇮🇷 IR
Operation Parliament
apt_group Information theft and espionage 🇵🇰 PK
Nomad Panda
apt_group Information theft and espionage 🇨🇳 CN
Magic Kitten
apt_group Information theft and espionage 🇮🇷 IR
Iron Group
apt_group Information theft and espionage 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
Operation Titan Rain
apt_group Information theft and espionage 🇨🇳 CN
Operation Ghoul
apt_group Information theft and espionage
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 03, 2026
Published DateMar 02, 2021