CVE-2021-26858

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 14 articles

EPSS Score

Source: FIRST.org · 2026-05-24
79.97%
probability
This CVE has a 79.97% probability of being exploited in the next 30 days.
0% Top 99.1th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Arbitrary file write

Google Project Zero

Patched
March 2, 2021
Reported by
Microsoft Threat Intelligence Center
Root Cause Analysis
???

Signal Intelligence

Confidence
92%
EPSS 79.97%
Mentions 14
Last Seen May 27, 2026

CNA Information

Analyst Note

CVE-2021-26858 is a confirmed zero-day in Microsoft Exchange Server 2019 with HIGH severity (CVSS 7.8) and documented RCE capability, corroborated by Google Project Zero research and CERT-EU security advisory. The vulnerability has sufficient evidence of active exploitation and technical validation to warrant high confidence in its confirmed status.

Threat Actors 39

APT 29
apt_group Information theft and espionage 🇷🇺 RU
WIZARD SPIDER
apt_group Financial gain 🇷🇺 RU
Cobalt
apt_group Financial crime 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
FIN7
apt_group Financial crime 🇷🇺 RU
EMISSARY PANDA
apt_group Information theft and espionage 🇨🇳 CN
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Harvester
apt_group Information theft and espionage Unknown
GOLD CABIN
apt_group 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
GhostEmperor
apt_group Information theft and espionage 🇨🇳 CN
Tick
apt_group Information theft and espionage 🇨🇳 CN
Infy
apt_group Information theft and espionage 🇮🇷 IR
GCHQ
apt_group Information theft and espionage 🇬🇧 GB
Cuboid Sandstorm
apt_group 🇮🇷 IR
Tortoiseshell
apt_group Information theft and espionage 🇮🇷 IR
[Unnamed group]
apt_group 🇨🇳 CN
Fox Kitten
apt_group Information theft and espionage 🇮🇷 IR
Attor
apt_group 🇷🇺 RU
PhantomCore
apt_group 🇷🇺 RU
Gray Sandstorm
apt_group 🇮🇷 IR
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Earth Baxia
apt_group Information theft and espionage 🇨🇳 CN
Operation Cobalt Whisper
apt_group Financial crime 🇨🇳 CN
UNC4841
apt_group Information theft and espionage 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Tonto Team
apt_group Information theft and espionage 🇨🇳 CN
Mikroceen
apt_group Information theft and espionage 🇨🇳 CN
CyberAv3ngers
apt_group Sabotage and destruction 🇮🇷 IR
Red October
apt_group 🇷🇺 RU
Night Dragon
apt_group Information theft and espionage 🇨🇳 CN
The White Company
apt_group Information theft and espionage 🇨🇳 CN
Calypso
apt_group Information theft and espionage 🇨🇳 CN
Operation Parliament
apt_group Information theft and espionage 🇵🇰 PK
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Operation Titan Rain
apt_group Information theft and espionage 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 03, 2026