CVE-2021-26855
Microsoft Exchange Server Remote Code Execution Vulnerability
9.1
CVSS 3.1
100.0 %
EPSS (current)
2021-11-03
KEV addition
Yes
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Microsoft / Exchange Server
Published: 2021-03-03 · Due (CISA): 2022-05-03
CWE: CWE-918 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | http/cves/2021/CVE-2021-26855.yaml | Microsoft Exchange Server SSRF Vulnerability | – |
| metasploit | auxiliary/gather/exchange_proxylogon_collector | auxiliary/gather/exchange_proxylogon_collector | 2021-03-02 |
| metasploit | auxiliary/scanner/http/exchange_proxylogon | auxiliary/scanner/http/exchange_proxylogon | 2021-03-02 |
| metasploit | exploit/windows/http/exchange_proxylogon_rce | exploit/windows/http/exchange_proxylogon_rce | 2021-03-02 |
| exploitdb | 49637 | Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC) | 2021-03-11 |
| exploitdb | 49663 | Microsoft Exchange 2019 - Server-Side Request Forgery | 2021-03-14 |
| exploitdb | 49879 | Microsoft Exchange 2019 - Unauthenticated Email Download | 2021-05-18 |
| exploitdb | 49895 | Microsoft Exchange 2019 - Unauthenticated Email Download (Metasploit) | 2021-05-21 |
References only — no downloads or instructions.