CVE-2021-26855

CRITICAL KEV RANSOMWARE NUCLEI

Microsoft Exchange ProxyLogon RCE

Title source: metasploit

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Exploits (67)

exploitdb WORKING POC
by mekhalleh · rubywebappswindows
https://www.exploit-db.com/exploits/49895
exploitdb WORKING POC
by Gonzalo Villegas · pythonwebappswindows
https://www.exploit-db.com/exploits/49879
exploitdb WORKING POC
by F5 · pythonremotewindows
https://www.exploit-db.com/exploits/49663
nomisec WORKING POC 252 stars
by Flangvik · remote
https://github.com/Flangvik/SharpProxyLogon
nomisec WORKING POC 177 stars
by hosch3n · remote
https://github.com/hosch3n/ProxyVulns
nomisec SCANNER 163 stars
by dwisiswant0 · infoleak
https://github.com/dwisiswant0/proxylogscan
nomisec WORKING POC 123 stars
by p0wershe11 · remote
https://github.com/p0wershe11/ProxyLogon
nomisec WORKING POC 100 stars
by h4x0r-dz · infoleak
https://github.com/h4x0r-dz/CVE-2021-26855
nomisec SCANNER 99 stars
by cert-lv · poc
https://github.com/cert-lv/exchange_webshell_detection
nomisec WORKING POC 61 stars
by hackerschoice · remote
https://github.com/hackerschoice/CVE-2021-26855
nomisec WORKING POC 53 stars
by alt3kx · infoleak
https://github.com/alt3kx/CVE-2021-26855_PoC
nomisec WORKING POC 51 stars
by praetorian-inc · remote
https://github.com/praetorian-inc/proxylogon-exploit
nomisec WORKING POC 36 stars
by conjojo · infoleak
https://github.com/conjojo/Microsoft_Exchange_Server_SSRF_CVE-2021-26855
nomisec WORKING POC 32 stars
by RickGeex · poc
https://github.com/RickGeex/ProxyLogon
nomisec WORKING POC 28 stars
by evilashz · remote
https://github.com/evilashz/ExchangeSSRFtoRCEExploit
nomisec WORKING POC 27 stars
by ZephrFish · remote
https://github.com/ZephrFish/Exch-CVE-2021-26855
nomisec WORKING POC 22 stars
by hakivvi · remote
https://github.com/hakivvi/proxylogon
nomisec WORKING POC 22 stars
by pussycat0x · infoleak
https://github.com/pussycat0x/CVE-2021-26855-SSRF
nomisec SCANNER 22 stars
by soteria-security · poc
https://github.com/soteria-security/HAFNIUM-IOC
nomisec WORKING POC 17 stars
by srvaccount · infoleak
https://github.com/srvaccount/CVE-2021-26855-PoC
nomisec WORKING POC 12 stars
by r0xDB · poc
https://github.com/r0xDB/CVE-2021-26855
nomisec WORKING POC 10 stars
by kh4sh3i · remote
https://github.com/kh4sh3i/ProxyLogon
nomisec WORKING POC 9 stars
by mil1200 · remote
https://github.com/mil1200/ProxyLogon-CVE-2021-26855
nomisec WORKING POC 8 stars
by thau0x01 · remote
https://github.com/thau0x01/poc_proxylogon
nomisec WORKING POC 6 stars
by Mr-xn · infoleak
https://github.com/Mr-xn/CVE-2021-26855-d
nomisec WORKING POC 6 stars
by La3B0z · poc
https://github.com/La3B0z/CVE-2021-26855-SSRF-Exchange
nomisec WRITEUP 5 stars
by SCS-Labs · poc
https://github.com/SCS-Labs/HAFNIUM-Microsoft-Exchange-0day
nomisec SCANNER 5 stars
by sgnls · poc
https://github.com/sgnls/exchange-0days-202103
nomisec WORKING POC 5 stars
by hackerxj007 · poc
https://github.com/hackerxj007/CVE-2021-26855
nomisec WORKING POC 4 stars
by ZephrFish · remote
https://github.com/ZephrFish/Exch-CVE-2021-26855_Priv
nomisec WORKING POC 4 stars
by mekhalleh · poc
https://github.com/mekhalleh/exchange_proxylogon
nomisec WORKING POC 4 stars
by TaroballzChen · remote
https://github.com/TaroballzChen/ProxyLogon-CVE-2021-26855-metasploit
nomisec SCANNER 4 stars
by KotSec · infoleak
https://github.com/KotSec/CVE-2021-26855-Scanner
nomisec WORKING POC 4 stars
by Yt1g3r · infoleak
https://github.com/Yt1g3r/CVE-2021-26855_SSRF
nomisec WORKING POC 3 stars
by ssrsec · remote
https://github.com/ssrsec/Microsoft-Exchange-RCE
nomisec WORKING POC 3 stars
by Immersive-Labs-Sec · poc
https://github.com/Immersive-Labs-Sec/ProxyLogon
gitlab WORKING POC 1 stars
by lucifer113 · poc
https://gitlab.com/lucifer113/ohwaa
nomisec WORKING POC 1 stars
by glen-pearson · remote
https://github.com/glen-pearson/ProxyLogon-CVE-2021-26855
gitlab WORKING POC
by gavz · poc
https://gitlab.com/gavz/ohwaa
gitlab WORKING POC
by swarupsro · poc
https://gitlab.com/swarupsro/ohwaa
gitlab WORKING POC
by rajivraj · poc
https://gitlab.com/rajivraj/ohwaa
gitlab WORKING POC
by d3viluke · poc
https://gitlab.com/d3viluke/ohwaa
nomisec WORKING POC
by SimoesCTT · poc
https://github.com/SimoesCTT/CTT-Exchange-RCE-v1.0---Microsoft-Exchange-Exploit-CVSS-10.0-CRITICAL-CVE-2021-26855-CVE-2021-27065
nomisec WRITEUP
by SimoesCTT · poc
https://github.com/SimoesCTT/CTT-ProxyLogon-RCE-v1.0---Convergent-Time-Theory-Enhanced-Microsoft-Exchange-Exploit
nomisec WORKING POC
by Wercd · remote
https://github.com/Wercd/CVE-2021-26855
github WORKING POC
by iitsmel · htmlpoc
https://github.com/iitsmel/Research/tree/main/CVE-2021-26855
nomisec NO CODE
by timb-machine-mirrors · infoleak
https://github.com/timb-machine-mirrors/testanull-CVE-2021-26855_read_poc.txt
nomisec WORKING POC
by ShyTangerine · poc
https://github.com/ShyTangerine/cve-2021-26855
nomisec WORKING POC
by TheDudeD6 · remote
https://github.com/TheDudeD6/ExchangeSmash
nomisec SUSPICIOUS
by 1342486672 · poc
https://github.com/1342486672/Flangvik
nomisec SUSPICIOUS
by yaoxiaoangry3 · poc
https://github.com/yaoxiaoangry3/Flangvik
nomisec WRITEUP
by Nick-Yin12 · poc
https://github.com/Nick-Yin12/106362522
nomisec WORKING POC
by haotiku · poc
https://github.com/haotiku/CVE-2021-26855-exploit-Exchange
nomisec STUB
by hictf · poc
https://github.com/hictf/CVE-2021-26855-CVE-2021-27065
nomisec SCANNER
by antichown · poc
https://github.com/antichown/Scan-Vuln-CVE-2021-26855
nomisec WORKING POC
by catmandx · remote
https://github.com/catmandx/CVE-2021-26855-Exchange-RCE
nomisec SCANNER
by DCScoder · poc
https://github.com/DCScoder/Exchange_IOC_Hunter
nomisec SCANNER
by mauricelambert · infoleak
https://github.com/mauricelambert/ExchangeWeaknessTest
metasploit SCANNER
by Orange Tsai, mekhalleh (RAMELLA Sébastien) · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/exchange_proxylogon.rb
exploitdb WORKING POC
pythonwebappswindows
https://www.exploit-db.com/exploits/49637
metasploit WORKING POC
by Orange Tsai, GreyOrder, mekhalleh (RAMELLA Sébastien) · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/exchange_proxylogon_collector.rb
patchapalooza WORKING POC
by securitystuffbackup · remote
https://gitlab.com/securitystuffbackup/SharpProxyLogon
patchapalooza WORKING POC
by gvillegas · infoleak
https://gitlab.com/gvillegas/ohwaa
patchapalooza WORKING POC
by r0xdeadbeef · remote
https://github.com/r0xdeadbeef/CVE-2021-26855
patchapalooza WORKING POC
by Udyz · remote
https://github.com/Udyz/Proxylogon

Nuclei Templates (1)

Microsoft Exchange Server SSRF Vulnerability
CRITICALby madrobot
Shodan: vuln:CVE-2021-26855 || http.favicon.hash:1768726119 || http.title:"outlook" || cpe:"cpe:2.3:a:microsoft:exchange_server"
FOFA: title="outlook" || icon_hash=1768726119

Scores

CVSS v3 9.1
EPSS 0.9436
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-03-02
InTheWild.io 2021-03-02
ENISA EUVD EUVD-2021-13639
Ransomware Use Confirmed
CWE
CWE-918
Status published
Products (3)
microsoft/exchange_server 2013 cumulative_update_21 (3 CPE variants)
microsoft/exchange_server 2016 cumulative_update_10 (12 CPE variants)
microsoft/exchange_server 2019 (9 CPE variants)
Published Mar 03, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026