CVE-2021-27065

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 15 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.16%
probability
This CVE has a 94.16% probability of being exploited in the next 30 days.
0% Top 99.9th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Arbitrary file write

Attack Intelligence

Google Project Zero

Patched
March 2, 2021
Reported by
Volexity, Orange Tsai from DEVCORE research team, and Microsoft Threat Intelligence Center (MSTIC)
Root Cause Analysis
???

Exploits & PoC

adamrpostjr/cve-2021-27065

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

11
1 repo — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
85%
EPSS 94.16%
Mentions 15
Last Seen May 27, 2026

CNA Information

Analyst Note

CVE-2021-27065 is confirmed as a zero-day RCE vulnerability in Microsoft Exchange Server with HIGH severity (CVSS 7.8) and inclusion in Google Project Zero, indicating credible security research validation. The CERT-EU security advisory corroborates the vulnerability's existence and active exploitation risk, though limited public documentation currently exists.

Threat Actors 47

APT 29
apt_group Information theft and espionage 🇷🇺 RU
Cobalt
apt_group Financial crime 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
EMISSARY PANDA
apt_group Information theft and espionage 🇨🇳 CN
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Harvester
apt_group Information theft and espionage Unknown
GOLD CABIN
apt_group 🇷🇺 RU
TA800
apt_group 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
GhostEmperor
apt_group Information theft and espionage 🇨🇳 CN
FusionCore
apt_group 🇪🇺 EU
DNSpionage
apt_group Information theft and espionage 🇮🇷 IR
Kinsing
apt_group 🇷🇺 RU
Tick
apt_group Information theft and espionage 🇨🇳 CN
Operation C-Major
apt_group Information theft and espionage 🇵🇰 PK
Infy
apt_group Information theft and espionage 🇮🇷 IR
GCHQ
apt_group Information theft and espionage 🇬🇧 GB
TeamTNT
apt_group 🇩🇪 DE
TA428
apt_group Information theft and espionage 🇨🇳 CN
Comment Crew
apt_group Information theft and espionage 🇨🇳 CN
Cuboid Sandstorm
apt_group 🇮🇷 IR
Tortoiseshell
apt_group Information theft and espionage 🇮🇷 IR
[Unnamed group]
apt_group 🇨🇳 CN
FamousSparrow
apt_group Information theft and espionage 🇨🇳 CN
Fox Kitten
apt_group Information theft and espionage 🇮🇷 IR
Attor
apt_group 🇷🇺 RU
PhantomCore
apt_group 🇷🇺 RU
Gray Sandstorm
apt_group 🇮🇷 IR
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Earth Baxia
apt_group Information theft and espionage 🇨🇳 CN
Operation Cobalt Whisper
apt_group Financial crime 🇨🇳 CN
UNC4841
apt_group Information theft and espionage 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Tonto Team
apt_group Information theft and espionage 🇨🇳 CN
PKPLUG
apt_group Information theft and espionage 🇨🇳 CN
Mikroceen
apt_group Information theft and espionage 🇨🇳 CN
CyberAv3ngers
apt_group Sabotage and destruction 🇮🇷 IR
Red October
apt_group 🇷🇺 RU
Night Dragon
apt_group Information theft and espionage 🇨🇳 CN
The White Company
apt_group Information theft and espionage 🇨🇳 CN
Calypso
apt_group Information theft and espionage 🇨🇳 CN
Operation Parliament
apt_group Information theft and espionage 🇵🇰 PK
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Operation Titan Rain
apt_group Information theft and espionage 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 03, 2026