Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft — Microsoft Exchange Server 2013 Cumulative Update 21
Microsoft Exchange Server Remote Code Execution Vulnerability
9.1
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Published
- Mar 3, 2021
- Modified
- Aug 19, 2026
- Added to KEV
- Nov 3, 2021
- Federal patch due
- May 3, 2022
CISA required action
Apply updates per vendor instructions.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2021-26855, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- Flangvik/SharpProxyLogon★ 247
C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection
updated Aug 7, 2026
- herwonowr/exprolog★ 186
ProxyLogon Full Exploit Chain PoC (CVE-2021–26855, CVE-2021–26857, CVE-2021–26858, CVE-2021–27065)
updated Jul 17, 2026
- hosch3n/ProxyVulns★ 176
[ProxyLogon] CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit. [ProxyOracle] CVE-2021-31195 & CVE-2021-31196 Exploit Chains. [ProxyShell] CVE-2021-34473 & CVE-2021-34523 & CVE-2021-31207 Exploit Chains.
updated Aug 17, 2026
- dwisiswant0/proxylogscan★ 165
A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin (CVE-2021-26855).
updated Aug 24, 2026
- p0wershe11/ProxyLogon★ 124
ProxyLogon(CVE-2021-26855+CVE-2021-27065) Exchange Server RCE(SSRF->GetWebShell)
updated May 23, 2026
- cert-lv/exchange_webshell_detection★ 99
Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065)
updated Jan 12, 2026
- h4x0r-dz/CVE-2021-26855★ 98
updated Aug 17, 2026
- hackerschoice/CVE-2021-26855★ 60
PoC of proxylogon chain SSRF(CVE-2021-26855) to write file by testanull, censored by github
updated Aug 17, 2026
References
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2021-26855?
Microsoft Exchange Server Remote Code Execution Vulnerability
How severe is CVE-2021-26855?
CVE-2021-26855 has a CVSS base score of 9.1 out of 10 (CVSS 3.1).
Is CVE-2021-26855 actively exploited in the wild?
Yes. CVE-2021-26855 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Nov 3, 2021, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2021-26855?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2021-26855?
Yes - a public Nuclei template referencing CVE-2021-26855 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2021-26855?
CVE-2021-26855 is classified under CWE-918 (CWE-918 Server-Side Request Forgery (SSRF)).
Cross-checked against
Impactr finds and proves whether CVE-2021-26855 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist