CVE-2021-26858
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
14 articles
EPSS Score
Source: FIRST.org · 2026-05-24
79.97%
probability
This CVE has a 79.97% probability
of being exploited in the next 30 days.
0%
Top 99.1th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroArbitrary file write
Google Project Zero
Patched
March 2, 2021
Reported by
Microsoft Threat Intelligence Center
Root Cause Analysis
???
The Microsoft Exchange hacks: How they started and where we are
BleepingComputer
Mar 16, 2021
State hackers rush to exploit unpatched Microsoft Exchange servers
BleepingComputer
Mar 03, 2021
Microsoft March 2021 Patch Tuesday fixes 82 flaws, 2 zero-days
BleepingComputer
Mar 09, 2021
Microsoft Exchange Server Zero-Days (ProxyLogon) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR
Qualys
Mar 03, 2021
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable-Research
May 27, 2026
Microsoft fixes actively exploited Exchange zero-day bugs, patch now
BleepingComputer
Mar 02, 2021
NSA Alert: Topmost CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors
Qualys
Oct 07, 2022
Security Advisory 2021-013
CERT-EU
Mar 03, 2021
Qualys Response to CISA Alert: Binding Operational Directive 22-01
Qualys
Nov 09, 2021
CISA Alert: Top Routinely Exploited Vulnerabilities
Qualys
Jul 29, 2021
Signal Intelligence
Confidence
92%
EPSS
79.97%
Mentions
14
Last Seen
May 27, 2026
CNA Information
Analyst Note
CVE-2021-26858 is a confirmed zero-day in Microsoft Exchange Server 2019 with HIGH severity (CVSS 7.8) and documented RCE capability, corroborated by Google Project Zero research and CERT-EU security advisory. The vulnerability has sufficient evidence of active exploitation and technical validation to warrant high confidence in its confirmed status.
Threat Actors 39
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
WIZARD SPIDER
apt_group
Financial gain
🇷🇺 RU
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
FIN7
apt_group
Financial crime
🇷🇺 RU
EMISSARY PANDA
apt_group
Information theft and espionage
🇨🇳 CN
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Harvester
apt_group
Information theft and espionage
Unknown
GOLD CABIN
apt_group
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
GhostEmperor
apt_group
Information theft and espionage
🇨🇳 CN
Tick
apt_group
Information theft and espionage
🇨🇳 CN
Infy
apt_group
Information theft and espionage
🇮🇷 IR
GCHQ
apt_group
Information theft and espionage
🇬🇧 GB
Cuboid Sandstorm
apt_group
🇮🇷 IR
Tortoiseshell
apt_group
Information theft and espionage
🇮🇷 IR
[Unnamed group]
apt_group
🇨🇳 CN
Fox Kitten
apt_group
Information theft and espionage
🇮🇷 IR
Attor
apt_group
🇷🇺 RU
PhantomCore
apt_group
🇷🇺 RU
Gray Sandstorm
apt_group
🇮🇷 IR
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Earth Baxia
apt_group
Information theft and espionage
🇨🇳 CN
Operation Cobalt Whisper
apt_group
Financial crime
🇨🇳 CN
UNC4841
apt_group
Information theft and espionage
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
Tonto Team
apt_group
Information theft and espionage
🇨🇳 CN
Mikroceen
apt_group
Information theft and espionage
🇨🇳 CN
CyberAv3ngers
apt_group
Sabotage and destruction
🇮🇷 IR
Red October
apt_group
🇷🇺 RU
Night Dragon
apt_group
Information theft and espionage
🇨🇳 CN
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Calypso
apt_group
Information theft and espionage
🇨🇳 CN
Operation Parliament
apt_group
Information theft and espionage
🇵🇰 PK
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Operation Titan Rain
apt_group
Information theft and espionage
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Beijing Group
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 03, 2026