CVE-2021-27065
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
15 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.16%
probability
This CVE has a 94.16% probability
of being exploited in the next 30 days.
0%
Top 99.9th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroArbitrary file write
Attack Intelligence
Google Project Zero
Patched
March 2, 2021
Reported by
Volexity, Orange Tsai from DEVCORE research team, and Microsoft Threat Intelligence Center (MSTIC)
Root Cause Analysis
???
Exploits & PoC
adamrpostjr/cve-2021-27065
Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.
11
1 repo — triés par ⭐
Rechercher sur GitHub ↗
The Microsoft Exchange hacks: How they started and where we are
BleepingComputer
Mar 16, 2021
Part 2: An In-Depth Look at the Latest Vulnerability Threat Landscape (Attackers’ Edition)
Qualys
Jul 18, 2023
State hackers rush to exploit unpatched Microsoft Exchange servers
BleepingComputer
Mar 03, 2021
Microsoft March 2021 Patch Tuesday fixes 82 flaws, 2 zero-days
BleepingComputer
Mar 09, 2021
Microsoft Exchange Server Zero-Days (ProxyLogon) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR
Qualys
Mar 03, 2021
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable-Research
May 27, 2026
Microsoft fixes actively exploited Exchange zero-day bugs, patch now
BleepingComputer
Mar 02, 2021
NSA Alert: Topmost CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors
Qualys
Oct 07, 2022
Security Advisory 2021-013
CERT-EU
Mar 03, 2021
Qualys Response to CISA Alert: Binding Operational Directive 22-01
Qualys
Nov 09, 2021
CISA Alert: Top Routinely Exploited Vulnerabilities
Qualys
Jul 29, 2021
Signal Intelligence
Confidence
85%
EPSS
94.16%
Mentions
15
Last Seen
May 27, 2026
CNA Information
Analyst Note
CVE-2021-27065 is confirmed as a zero-day RCE vulnerability in Microsoft Exchange Server with HIGH severity (CVSS 7.8) and inclusion in Google Project Zero, indicating credible security research validation. The CERT-EU security advisory corroborates the vulnerability's existence and active exploitation risk, though limited public documentation currently exists.
Threat Actors 47
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
EMISSARY PANDA
apt_group
Information theft and espionage
🇨🇳 CN
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Harvester
apt_group
Information theft and espionage
Unknown
GOLD CABIN
apt_group
🇷🇺 RU
TA800
apt_group
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
GhostEmperor
apt_group
Information theft and espionage
🇨🇳 CN
FusionCore
apt_group
🇪🇺 EU
DNSpionage
apt_group
Information theft and espionage
🇮🇷 IR
Kinsing
apt_group
🇷🇺 RU
Tick
apt_group
Information theft and espionage
🇨🇳 CN
Operation C-Major
apt_group
Information theft and espionage
🇵🇰 PK
Infy
apt_group
Information theft and espionage
🇮🇷 IR
GCHQ
apt_group
Information theft and espionage
🇬🇧 GB
TeamTNT
apt_group
🇩🇪 DE
TA428
apt_group
Information theft and espionage
🇨🇳 CN
Comment Crew
apt_group
Information theft and espionage
🇨🇳 CN
Cuboid Sandstorm
apt_group
🇮🇷 IR
Tortoiseshell
apt_group
Information theft and espionage
🇮🇷 IR
[Unnamed group]
apt_group
🇨🇳 CN
FamousSparrow
apt_group
Information theft and espionage
🇨🇳 CN
Fox Kitten
apt_group
Information theft and espionage
🇮🇷 IR
Attor
apt_group
🇷🇺 RU
PhantomCore
apt_group
🇷🇺 RU
Gray Sandstorm
apt_group
🇮🇷 IR
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Earth Baxia
apt_group
Information theft and espionage
🇨🇳 CN
Operation Cobalt Whisper
apt_group
Financial crime
🇨🇳 CN
UNC4841
apt_group
Information theft and espionage
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
Tonto Team
apt_group
Information theft and espionage
🇨🇳 CN
PKPLUG
apt_group
Information theft and espionage
🇨🇳 CN
Mikroceen
apt_group
Information theft and espionage
🇨🇳 CN
CyberAv3ngers
apt_group
Sabotage and destruction
🇮🇷 IR
Red October
apt_group
🇷🇺 RU
Night Dragon
apt_group
Information theft and espionage
🇨🇳 CN
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Calypso
apt_group
Information theft and espionage
🇨🇳 CN
Operation Parliament
apt_group
Information theft and espionage
🇵🇰 PK
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Operation Titan Rain
apt_group
Information theft and espionage
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Beijing Group
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 03, 2026