CVE-2021-26855

ENISA EUVD: EUVD-2021-13639 ↗
Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 20 articles Published: 2021-03-02

EPSS Score

Source: FIRST.org · 2026-05-23
94.34%
probability
This CVE has a 94.34% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
9.1
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Temporal
Exploit Code Maturity
Functional
Remediation Level
Official Fix
Report Confidence
Confirmed
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:F/RL:O/RC:C

CVSS v2 (legacy)

7.5
HIGH
Access Vector
Network
Access Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

NVD
Microsoft Exchange Server Remote Code Execution Vulnerability

Affected Products

Microsoft
Microsoft Exchange Server 2016 Cumulative Update 19
15.01.0
Microsoft
Microsoft Exchange Server 2019 Cumulative Update 8
15.02.0
Microsoft
Microsoft Exchange Server 2019
15.02.0
Microsoft
Microsoft Exchange Server 2013 Cumulative Update 22
15.00.0
Microsoft
Microsoft Exchange Server 2019 Cumulative Update 2
15.02.0

Attack Intelligence

Google Project Zero

Patched
March 2, 2021
Reported by
Volexity, Orange Tsai from DEVCORE research team, and Microsoft Threat Intelligence Center (MSTIC)
Root Cause Analysis
https://googleprojectzero.github.io/0days-in-the-wild/0day-RCAs/2021/CVE-2021-26855.html

Exploits & PoC

Flangvik/SharpProxyLogon

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

249 2021-03-31
hosch3n/ProxyVulns

[ProxyLogon] CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit. [ProxyOracle] CVE-2021-31195 & CVE-2021-31196 Exploit Chains. [ProxyShell]

177 2022-10-21
dwisiswant0/proxylogscan

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as th

164 2022-03-02
p0wershe11/ProxyLogon

ProxyLogon(CVE-2021-26855+CVE-2021-27065) Exchange Server RCE(SSRF->GetWebShell)

124 2021-03-17
cert-lv/exchange_webshell_detection

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857, CVE-202

99 2021-03-16
hackerschoice/CVE-2021-26855

PoC of proxylogon chain SSRF(CVE-2021-26855) to write file by testanull, censored by github

60 2021-03-11
praetorian-inc/proxylogon-exploit

Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.

51 2021-03-24
conjojo/Microsoft_Exchange_Server_SSRF_CVE-2021-26855

Microsoft Exchange Server SSRF漏洞(CVE-2021-26855)

36 2021-03-06
RickGeex/ProxyLogon

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authent

32 2021-05-01
ZephrFish/Exch-CVE-2021-26855

CVE-2021-26855: PoC (Not a HoneyPoC for once!)

29 2025-04-26
evilashz/ExchangeSSRFtoRCEExploit

CVE-2021-26855 & CVE-2021-27065

28 2021-03-15
soteria-security/HAFNIUM-IOC

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

22 2021-03-05
pussycat0x/CVE-2021-26855-SSRF

This script helps to identify CVE-2021-26855 ssrf Poc

22 2021-03-10
hakivvi/proxylogon

RCE exploit for Microsoft Exchange Server (CVE-2021-26855).

22 2022-04-23
srvaccount/CVE-2021-26855-PoC

PoC exploit code for CVE-2021-26855

17 2021-03-09
r0xDB/CVE-2021-26855

CVE-2021-26855, also known as Proxylogon, is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send arbitrar

12 2024-01-01
mil1200/ProxyLogon-CVE-2021-26855

RCE exploit for ProxyLogon vulnerability in Microsoft Exchange

9 2021-03-14
kh4sh3i/ProxyLogon

ProxyLogon (CVE-2021-26855+CVE-2021-27065) Exchange Server RCE (SSRF->GetWebShell)

9 2023-03-28
thau0x01/poc_proxylogon

Microsoft Exchange ProxyLogon PoC (CVE-2021-26855)

8 2022-02-10
La3B0z/CVE-2021-26855-SSRF-Exchange

CVE-2021-26855 SSRF Exchange Server

6 2021-03-06
sgnls/exchange-0days-202103

IoC determination for exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.

5 2021-03-15
hackerxj007/CVE-2021-26855

CVE-2021-26855 exp

5 2021-03-08
SCS-Labs/HAFNIUM-Microsoft-Exchange-0day

CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065

5 2021-04-19
mekhalleh/exchange_proxylogon

Module pack for #ProxyLogon (part. of my contribute for Metasploit-Framework) [CVE-2021-26855 && CVE-2021-27065]

4 2021-03-29
Yt1g3r/CVE-2021-26855_SSRF

POC of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865, ProxyLogon poc

4 2021-03-11
4 2025-12-07
TaroballzChen/ProxyLogon-CVE-2021-26855-metasploit

CVE-2021-26855 proxyLogon metasploit exploit script

4 2021-03-17
KotSec/CVE-2021-26855-Scanner

Scanner and PoC for CVE-2021-26855

3 2021-03-12
Immersive-Labs-Sec/ProxyLogon

Chaining CVE-2021-26855 and CVE-2021-26857 to exploit Microsoft Exchange

3 2021-03-22
ssrsec/Microsoft-Exchange-RCE

Microsoft Exchange CVE-2021-26855&CVE-2021-27065

3 2023-02-02
mauricelambert/ExchangeWeaknessTest

This script test the CVE-2021-26855 vulnerability on Exchange Server.

0 2021-03-09
DCScoder/Exchange_IOC_Hunter

CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065

0 2021-03-17
catmandx/CVE-2021-26855-Exchange-RCE

Microsoft Exchange Proxylogon Exploit Chain EXP分析

0 2021-03-18
hictf/CVE-2021-26855-CVE-2021-27065

analytics ProxyLogo Mail exchange RCE

0 2021-03-23
Nick-Yin12/106362522

針對近期微軟公布修補遭駭客攻擊的Exchange Server漏洞問題,台灣DEVCORE表示早在1月5日便已發現安全漏洞後,並且向微軟通報此項編號命名為「CVE-2021-26855 」,以及「CVE-2021-27065」的零日漏洞,同時也將此項漏洞稱為「ProxyLogon」。 此次揭露的「

0 2021-04-19
yaoxiaoangry3/Flangvik

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…

0 2021-10-30
1342486672/Flangvik

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…

0 2022-06-07
0 2022-06-24
SimoesCTT/CTT-ProxyLogon-RCE-v1.0---Convergent-Time-Theory-Enhanced-Microsoft-Exchange-Exploit

An advanced exploit for Microsoft Exchange Server (CVE-2021-26855, CVE-2021-27065) enhanced with Convergent Time Theory principles, achieving near-pe

0 2026-01-27
SimoesCTT/CTT-Exchange-RCE-v1.0---Microsoft-Exchange-Exploit-CVSS-10.0-CRITICAL-CVE-2021-26855-CVE-2021-27065

CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that affec

0 2026-01-28
49 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 94.34%
CVSS v3.1 9.1
Mentions 20
Last Seen Feb 25, 2025

CNA Information

CNA Assigner
microsoft
CNA Title
Microsoft Exchange Server Remote Code Execution Vulnerability

Analyst Note

CVE-2021-26855 is a critical RCE vulnerability in Microsoft Exchange Server with a CVSS score of 9.1, reported by Google Project Zero and documented in official security advisories (CERT-EU). The confirmed status is strongly supported by the zero-day classification from a trusted security research organization and immediate vendor attention.

Threat Actors 61

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Turla Group
apt_group Information theft and espionage Russian Federation
APT 29
apt_group Information theft and espionage 🇷🇺 RU
Mustang Panda
apt_group Information theft and espionage 🇨🇳 CN
WIZARD SPIDER
apt_group Financial gain 🇷🇺 RU
Cobalt
apt_group Financial crime 🇷🇺 RU
APT37
apt_group Information theft and espionage 🇰🇵 KP
APT 28
apt_group Information theft and espionage 🇷🇺 RU
FIN7
apt_group Financial crime 🇷🇺 RU
EMISSARY PANDA
apt_group Information theft and espionage 🇨🇳 CN
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Vicious Panda
apt_group Information theft and espionage 🇨🇳 CN
Careto
apt_group Information theft and espionage 🇪🇸 ES
GOLD CABIN
apt_group 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
GhostEmperor
apt_group Information theft and espionage 🇨🇳 CN
SCATTERED SPIDER
apt_group Financial crime 🇺🇸 US
Watchdog
apt_group 🇨🇳 CN
Ice Fog
apt_group Information theft and espionage 🇨🇳 CN
Tick
apt_group Information theft and espionage 🇨🇳 CN
APT3
apt_group Information theft and espionage 🇨🇳 CN
Infy
apt_group Information theft and espionage 🇮🇷 IR
Naikon
apt_group Information theft and espionage 🇨🇳 CN
GCHQ
apt_group Information theft and espionage 🇬🇧 GB
TA428
apt_group Information theft and espionage 🇨🇳 CN
Silence group
apt_group Financial crime 🇷🇺 RU
APT42
apt_group Information theft and espionage 🇮🇷 IR
Tortoiseshell
apt_group Information theft and espionage 🇮🇷 IR
[Unnamed group]
apt_group 🇨🇳 CN
Fox Kitten
apt_group Information theft and espionage 🇮🇷 IR
Attor
apt_group 🇷🇺 RU
PhantomCore
apt_group 🇷🇺 RU
Returned Libra
apt_group 🇨🇳 CN
Head Mare
apt_group 🇺🇦 UA
Earth Baxia
apt_group Information theft and espionage 🇨🇳 CN
CoughingDown
apt_group 🇨🇳 CN
Flax Typhoon
apt_group Information theft and espionage 🇨🇳 CN
Operation Cobalt Whisper
apt_group Financial crime 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Tonto Team
apt_group Information theft and espionage 🇨🇳 CN
PKPLUG
apt_group Information theft and espionage 🇨🇳 CN
Mikroceen
apt_group Information theft and espionage 🇨🇳 CN
Red October
apt_group 🇷🇺 RU
Night Dragon
apt_group Information theft and espionage 🇨🇳 CN
The White Company
apt_group Information theft and espionage 🇨🇳 CN
Pat Bear
apt_group 🇸🇾 SY
Calypso
apt_group Information theft and espionage 🇨🇳 CN
ExCobalt
apt_group 🇷🇺 RU
Unnamed Actor
apt_group 🇨🇳 CN
TA2552
apt_group Information theft and espionage 🇮🇷 IR
Operation Parliament
apt_group Information theft and espionage 🇵🇰 PK
Nomad Panda
apt_group Information theft and espionage 🇨🇳 CN
Magic Kitten
apt_group Information theft and espionage 🇮🇷 IR
Iron Group
apt_group Information theft and espionage 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
Operation Titan Rain
apt_group Information theft and espionage 🇨🇳 CN
Operation Ghoul
apt_group Information theft and espionage
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 03, 2026
Published DateMar 02, 2021