logo

Microsoft Exchange Zero-Day Vulnerabilities Exploited

ID: 5ae11ff8-5298-5870-b747-8ed3a66a0c9e

STIX ID: report--5ae11ff8-5298-5870-b747-8ed3a66a0c9e

Feed Name: Arctic Wolf Blog

Threat Score
90/100

Date Published: 2021-03-01

Date Updated: 2026-04-26

...
...

Microsoft released an out-of-band patch for multiple critical Exchange vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) that have been actively exploited by the China-linked HAFNIUM group since at least January 6, 2021; attackers chained SSRF, insecure deserialization, and post-auth arbitrary file-write flaws to achieve SYSTEM-level code execution and full mailbox access on on-prem Exchange 2013/2016/2019, and Arctic Wolf is updating detections and monitoring customer environments for related IOCs and TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.