logo

Coverage Advisory For MS Exchange Server Vulnerabilities

ID: 16def88b-05f6-59d1-94f9-99809a88e363

STIX ID: report--16def88b-05f6-59d1-94f9-99809a88e363

Feed Name: Zscaler Security Research Blog

Threat Score
88/100

Date Published: 2025-07-03

Date Updated: 2026-05-01

...
...

This report describes active exploitation of two Microsoft Exchange zero-day vulnerabilities (CVE-2022-41040 and CVE-2022-41082, aka ProxyNotShell) that were chained by threat actors to deploy a Chopper web shell, conduct Active Directory reconnaissance and exfiltrate data; Microsoft and CISA issued guidance and hotfixes, and Zscaler published mitigations and protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.