Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPsCisco Talos·May 7, 19:50 UTC · May 7, 2021Exploit / PoCCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs160
Exchange Servers targeted via zero-day exploits, have yours been hit?Help Net Security·Mar 15, 12:57 UTC · Mar 15, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
No, I Did Not Hack Your MS Exchange ServerKrebs on Security·Mar 28, 18:16 UTC · Mar 28, 2021Exploit / PoC in the wild60
Microsoft: Two New 0-Day Flaws in Exchange ServerKrebs on Security·Sep 30, 17:03 UTC · Sep 30, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-41082160
U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 16, 17:31 UTC · May 16, 2026Exploit / PoC in the wildCVE-2026-4289760
17,000+ Microsoft Exchange servers in Germany are vulnerable to attack, BSI warnsHelp Net Security·Mar 26, 00:00 UTC · Mar 26, 2024Exploit / PoC in the wildCVE-2024-21410CVE-2024-2619860
At Least 30,000 U.S. Organizations Newly Hacked Via Holes in Microsoft’s Email SoftwareKrebs on Security·Mar 29, 08:27 UTC · Mar 29, 2021Exploit / PoC60
Microsoft: Chinese Cyberspies Used 4 Exchange Server Flaws to Plunder EmailsKrebs on Security·Mar 2, 22:16 UTC · Mar 2, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
FBI removes web shells from hacked Microsoft Exchange serversHelp Net Security·Apr 14, 00:00 UTC · Apr 14, 2021Exploit / PoC160
URGENT — 4 Actively Exploited 0The Hacker News·Mar 3, 07:56 UTC · Mar 3, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Chinese hackers hit thousands of organizations using Microsoft ExchangeSecurity Affairs·Mar 9, 19:09 UTC · Mar 9, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Microsoft releases IOC Detection Tool for Microsoft Exchange Server flawsSecurity Affairs·Mar 6, 16:50 UTC · Mar 6, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
As attacks on Exchange servers escalate, Microsoft investigates potential PoC exploit leakHelp Net Security·Mar 15, 00:00 UTC · Mar 15, 2021Exploit / PoCCVE-2021-2685560
FBI silently removed web shells planted on Microsoft Exchange serversSecurity Affairs·Apr 14, 10:20 UTC · Apr 14, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Microsoft updated MSERT to detect web shells used in attacks against Microsoft Exchange installsSecurity Affairs·Mar 8, 13:11 UTC · Mar 8, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Microsoft fixes 2 critical Exchange Server flaws reported by the NSASecurity Affairs·Apr 13, 21:05 UTC · Apr 13, 2021Exploit / PoCCVE-2021-28480CVE-2021-28481CVE-2021-28482+1 CVEs60
Critical Exchange Server Flaw (CVE-2024The Hacker News·Feb 17, 07:27 UTC · Feb 17, 2024Exploit / PoC in the wildCVE-2024-21410CVE-2024-21351CVE-2024-21412+1 CVEs160
Microsoft Expands Coverage for Exchange Server BugsInfosecurity Magazine·Mar 10, 09:38 UTC · Mar 10, 2021Exploit / PoC in the wildCVE-2021-26411CVE-2021-27077CVE-2020-0792+4 CVEs60
Zero-day vulnerabilities in Microsoft Exchange ServerKaspersky Securelist·Mar 4, 17:20 UTC · Mar 4, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Hafnium Update: Continued Microsoft Exchange Server ExploitationCisco Talos·Mar 10, 00:52 UTC · Mar 10, 2021Exploit / PoC60
Microsoft confirms two Exchange Server zero days are being used in cyberattacksThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Exploit / PoC in the wildCVE-2022-41040CVE-2022-41082160
Actively exploited MS Exchange flaw present on 80% of exposed serversHelp Net Security·Apr 8, 00:00 UTC · Apr 8, 2020Exploit / PoC in the wildCVE-2020-068860
GitHub removes researcher's Exchange Server exploit, sparking industry debateCyberScoop·Mar 11, 21:25 UTC · Mar 11, 2021Exploit / PoC in the wild60
Microsoft: Chinese APT Targeted Exchange Servers With Four ZeroThe Record·Jan 30, 00:00 UTC · Jan 30, 2023Exploit / PoCCVE-2021-26855CVE-2021-26857CVE-2021-26858+4 CVEs60
Four zero-days in Microsoft Exchange actively exploited in the wildSecurity Affairs·Mar 3, 01:23 UTC · Mar 3, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Victims of Microsoft Exchange Server zeroCyberScoop·Mar 5, 15:14 UTC · Mar 5, 2021Exploit / PoC in the wild60
Microsoft Exchange admins advised to expand antivirus scanningHelp Net Security·Feb 27, 00:00 UTC · Feb 27, 2023Exploit / PoC60
Expert released PoC code for Microsoft Exchange CVE-2021Security Affairs·Nov 23, 17:14 UTC · Nov 23, 2021Exploit / PoC in the wildCVE-2021-4232160
CISA, Microsoft warn of critical Exchange hybrid flaw CVE-2025Security Affairs·Aug 7, 14:05 UTC · Aug 7, 2025Exploit / PoC in the wildCVE-2025-5378660
Hackers compromised the Microsoft Exchange servers at EBASecurity Affairs·Mar 8, 15:17 UTC · Mar 8, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
U.S. CISA adds Adobe, Fortinet, Microsoft Windows, Microsoft Exchange Server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 14, 07:38 UTC · Apr 14, 2026Exploit / PoC in the wildCVE-2026-34621CVE-2012-1854CVE-2020-9715+4 CVEs260
Max-severity Exchange server flaw under active exploitation by Kremlin hackersArs Technica · Security·Jul 30, 20:57 UTC · Jul 30, 2026Exploit / PoC in the wildCVE-2026-4289760
Italian authorities arrest Chinese man over Microsoft Exchange Server hack, targeting of COVIDCyberScoop·Jul 8, 19:45 UTC · Jul 8, 2025Exploit / PoC in the wild60
Russia’s SVR spy agency scanned for Microsoft Exchange Server bug, UK and US sayCyberScoop·May 7, 17:05 UTC · May 7, 2021Exploit / PoC in the wild160
ProxyNotShellThe Hacker News·Oct 4, 10:19 UTC · Oct 4, 2022Exploit / PoCCVE-2022-41040CVE-2022-41082CVE-2021-34523+2 CVEs60
ProxyLogon fixes for unsupported Microsoft Exchange versions releasedSecurity Affairs·Mar 9, 17:11 UTC · Mar 9, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
APTs are exploiting CVE-2020Security Affairs·Mar 9, 12:05 UTC · Mar 9, 2020Exploit / PoCCVE-2020-068860
ProxyLogon PoC Exploit Released; Likely to Fuel More Disruptive Cyber AttacksThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2021Exploit / PoC in the wildCVE-2021-2685560
Microsoft Fixes Exchange Server ZeroInfosecurity Magazine·May 12, 10:50 UTC · May 12, 2021Exploit / PoC in the wildCVE-2021-31207CVE-2021-31200CVE-2021-31204+2 CVEs60
Talos Takes Ep. #43: What you should know about the Microsoft Exchange Server zeroCisco Talos·Mar 5, 14:33 UTC · Mar 5, 2021Exploit / PoC60