logo

Critical Microsoft Exchange Flaw: What is CVE-2021-26855? | UpGuard

ID: 71fc7f66-c800-57ec-9637-f58d55c4c468

STIX ID: report--71fc7f66-c800-57ec-9637-f58d55c4c468

Feed Name: UpGuard Blog

Threat Score
90/100

Date Published: 2025-02-14

Date Updated: 2026-05-01

...
...

Hafnium exploited four Microsoft Exchange Server zero-day vulnerabilities beginning 6 January 2021, resulting in widespread compromises (≈60,000 organizations) via chained SSRF-to-RCE flaws, web shells and data exfiltration; Microsoft released patches on 2 March 2021 and the report provides IOC, detection, patching and CISA response guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.