Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPsCisco Talos·May 7, 19:50 UTC · May 7, 2021Exploit / PoCCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs160
Exchange Servers targeted via zero-day exploits, have yours been hit?Help Net Security·Mar 15, 12:57 UTC · Mar 15, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Chinese hackers hit thousands of organizations using Microsoft ExchangeSecurity Affairs·Mar 9, 19:09 UTC · Mar 9, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
CISA, Microsoft warn of critical Exchange hybrid flaw CVE-2025Security Affairs·Aug 7, 14:05 UTC · Aug 7, 2025Exploit / PoC in the wildCVE-2025-5378660
Microsoft updated MSERT to detect web shells used in attacks against Microsoft Exchange installsSecurity Affairs·Mar 8, 13:11 UTC · Mar 8, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Microsoft: Two New 0-Day Flaws in Exchange ServerKrebs on Security·Sep 30, 17:03 UTC · Sep 30, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-41082160
No, I Did Not Hack Your MS Exchange ServerKrebs on Security·Mar 28, 18:16 UTC · Mar 28, 2021Exploit / PoC in the wild60
At Least 30,000 U.S. Organizations Newly Hacked Via Holes in Microsoft’s Email SoftwareKrebs on Security·Mar 29, 08:27 UTC · Mar 29, 2021Exploit / PoC60
Expert released PoC code for Microsoft Exchange CVE-2021Security Affairs·Nov 23, 17:14 UTC · Nov 23, 2021Exploit / PoC in the wildCVE-2021-4232160
As attacks on Exchange servers escalate, Microsoft investigates potential PoC exploit leakHelp Net Security·Mar 15, 00:00 UTC · Mar 15, 2021Exploit / PoCCVE-2021-2685560
Microsoft releases IOC Detection Tool for Microsoft Exchange Server flawsSecurity Affairs·Mar 6, 16:50 UTC · Mar 6, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Four zero-days in Microsoft Exchange actively exploited in the wildSecurity Affairs·Mar 3, 01:23 UTC · Mar 3, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
CISA emergency directive urges to fix Microsoft Exchange zeroSecurity Affairs·Mar 4, 14:41 UTC · Mar 4, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Actively exploited MS Exchange flaw present on 80% of exposed serversHelp Net Security·Apr 8, 00:00 UTC · Apr 8, 2020Exploit / PoC in the wildCVE-2020-068860
U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 16, 17:31 UTC · May 16, 2026Exploit / PoC in the wildCVE-2026-4289760
17,000+ Microsoft Exchange servers in Germany are vulnerable to attack, BSI warnsHelp Net Security·Mar 26, 00:00 UTC · Mar 26, 2024Exploit / PoC in the wildCVE-2024-21410CVE-2024-2619860
Microsoft Exchange admins advised to expand antivirus scanningHelp Net Security·Feb 27, 00:00 UTC · Feb 27, 2023Exploit / PoC60
ProxyLogon fixes for unsupported Microsoft Exchange versions releasedSecurity Affairs·Mar 9, 17:11 UTC · Mar 9, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
URGENT — 4 Actively Exploited 0The Hacker News·Mar 3, 07:56 UTC · Mar 3, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Microsoft: Chinese Cyberspies Used 4 Exchange Server Flaws to Plunder EmailsKrebs on Security·Mar 2, 22:16 UTC · Mar 2, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
PoC exploit code for ProxyNotShell Microsoft Exchange bugs released onlineSecurity Affairs·Nov 20, 19:41 UTC · Nov 20, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-4108260
Microsoft Exchange ProxyToken flaw can allow attackers to read your emailsSecurity Affairs·Aug 31, 10:16 UTC · Aug 31, 2021Exploit / PoCCVE-2021-3376660
FBI silently removed web shells planted on Microsoft Exchange serversSecurity Affairs·Apr 14, 10:20 UTC · Apr 14, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Microsoft: Chinese APT Targeted Exchange Servers With Four ZeroThe Record·Jan 30, 00:00 UTC · Jan 30, 2023Exploit / PoCCVE-2021-26855CVE-2021-26857CVE-2021-26858+4 CVEs60
Microsoft Confirms Two Exchange ZeroInfosecurity Magazine·Sep 30, 15:30 UTC · Sep 30, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-4108260
Microsoft confirms Exchange zeroSecurity Affairs·Sep 30, 10:18 UTC · Sep 30, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-4108260
Expert released PoC exploit for Microsoft Exchange flawSecurity Affairs·May 3, 21:08 UTC · May 3, 2021Exploit / PoCCVE-2021-28482CVE-2021-28480CVE-2021-28481+1 CVEs160
FBI removes web shells from hacked Microsoft Exchange serversHelp Net Security·Apr 14, 00:00 UTC · Apr 14, 2021Exploit / PoC160
Microsoft fixes 2 critical Exchange Server flaws reported by the NSASecurity Affairs·Apr 13, 21:05 UTC · Apr 13, 2021Exploit / PoCCVE-2021-28480CVE-2021-28481CVE-2021-28482+1 CVEs60
Expert publishes PoC exploit code for Microsoft Exchange flawsSecurity Affairs·Mar 11, 21:33 UTC · Mar 11, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs160
Microsoft confirms two Exchange Server zero days are being used in cyberattacksThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Exploit / PoC in the wildCVE-2022-41040CVE-2022-41082160
Microsoft mitigations for recently disclosed Exchange zeroSecurity Affairs·Oct 4, 06:40 UTC · Oct 4, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-4108260
Is there a link between Microsoft Exchange exploits and PoC code the company shared with partner security firms?Security Affairs·Mar 16, 07:48 UTC · Mar 16, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+2 CVEs60
Hackers compromised the Microsoft Exchange servers at EBASecurity Affairs·Mar 8, 15:17 UTC · Mar 8, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Zero-day vulnerabilities in Microsoft Exchange ServerKaspersky Securelist·Mar 4, 17:20 UTC · Mar 4, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
APTs are exploiting CVE-2020Security Affairs·Mar 9, 12:05 UTC · Mar 9, 2020Exploit / PoCCVE-2020-068860
Critical Exchange Server Flaw (CVE-2024The Hacker News·Feb 17, 07:27 UTC · Feb 17, 2024Exploit / PoC in the wildCVE-2024-21410CVE-2024-21351CVE-2024-21412+1 CVEs160
Hafnium Update: Continued Microsoft Exchange Server ExploitationCisco Talos·Mar 10, 00:52 UTC · Mar 10, 2021Exploit / PoC60
NightEagle APT Exploits Microsoft Exchange Flaw to Target China's Military and Tech SectorsThe Hacker News·Jul 10, 04:17 UTC · Jul 10, 2025Exploit / PoC60