logo

Coverage Advisory for Zero-day Exploits Related to MS-Office

ID: db0674a9-d438-5da6-9aaf-0d39ed4ae973

STIX ID: report--db0674a9-d438-5da6-9aaf-0d39ed4ae973

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** Microsoft reported active exploitation of multiple on-premises Microsoft Exchange Server vulnerabilities (including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) by the HAFNIUM actor, enabling web shell deployment, data access, and subsequent installation of malware such as the DearCry ransomware; Microsoft and Zscaler published detection, mitigation guidance, and signatures to help identify and protect affected Exchange servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.