Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of CredentialsPalo Alto Unit 42·Jun 6, 13:23 UTC · Jun 6, 2024Vulnerability in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Exchange Servers targeted via zero-day exploits, have yours been hit?Help Net Security·Mar 15, 12:57 UTC · Mar 15, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
No, I Did Not Hack Your MS Exchange ServerKrebs on Security·Mar 28, 18:16 UTC · Mar 28, 2021Exploit / PoC in the wild60
Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)Palo Alto Unit 42·Jun 5, 17:51 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-41040CVE-2022-41082CVE-2021-34473+2 CVEs60
German BSI warns of 17K unpatched Microsoft Exchange serversSecurity Affairs·Mar 30, 08:28 UTC · Mar 30, 2024Vulnerability in the wildCVE-2024-2141060
Attacks on Exchange servers expand from nationThe Record·Nov 17, 06:58 UTC · Nov 17, 2022Ransomware in the wild60
CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zeroSecurity Affairs·May 15, 14:04 UTC · May 15, 2026Vulnerability in the wildCVE-2026-42897CVE-2023-21529160
Microsoft: Two New 0-Day Flaws in Exchange ServerKrebs on Security·Sep 30, 17:03 UTC · Sep 30, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-41082160
Microsoft Exchange Cyber Attack — What Do We Know So Far?The Hacker News·Mar 10, 08:44 UTC · Mar 10, 2021Data breach in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
More than 46,000 Exchange servers still unpatchedThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Vulnerability in the wild60
U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 16, 17:31 UTC · May 16, 2026Exploit / PoC in the wildCVE-2026-4289760
17,000+ Microsoft Exchange servers in Germany are vulnerable to attack, BSI warnsHelp Net Security·Mar 26, 00:00 UTC · Mar 26, 2024Exploit / PoC in the wildCVE-2024-21410CVE-2024-2619860
Microsoft: Chinese Cyberspies Used 4 Exchange Server Flaws to Plunder EmailsKrebs on Security·Mar 2, 22:16 UTC · Mar 2, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
November 2025 Patch Tuesday forecast: Windows Exchange Server EOL?Help Net Security·Nov 12, 11:13 UTC · Nov 12, 2025Vulnerability in the wildCVE-2025-62215CVE-2025-59287160
NSA Discovers New Vulnerabilities Affecting Microsoft Exchange ServersThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2021Vulnerability in the wildCVE-2021-28310CVE-2021-1732CVE-2021-28480+6 CVEs60
URGENT — 4 Actively Exploited 0The Hacker News·Mar 3, 07:56 UTC · Mar 3, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Chinese hackers hit thousands of organizations using Microsoft ExchangeSecurity Affairs·Mar 9, 19:09 UTC · Mar 9, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange ServersThe Hacker News·Nov 1, 13:31 UTC · Nov 1, 2025Vulnerability in the wildCVE-2025-59287260
Microsoft releases IOC Detection Tool for Microsoft Exchange Server flawsSecurity Affairs·Mar 6, 16:50 UTC · Mar 6, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
With court order, FBI removes hundreds of Exchange Server web shells from US organizationsCyberScoop·Apr 14, 00:47 UTC · Apr 14, 2021Policy & legal in the wild60
CISA, NSA offer guidance to better protect Microsoft Exchange ServersCyberScoop·Oct 30, 22:00 UTC · Oct 30, 2025Ransomware in the wildCVE-2025-5378660
62,000 Microsoft Exchange Servers potentially left unpatchedSecurity Affairs·Mar 25, 18:03 UTC · Mar 25, 2021Vulnerability in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
FBI silently removed web shells planted on Microsoft Exchange serversSecurity Affairs·Apr 14, 10:20 UTC · Apr 14, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Microsoft updated MSERT to detect web shells used in attacks against Microsoft Exchange installsSecurity Affairs·Mar 8, 13:11 UTC · Mar 8, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Threat Advisory: Microsoft warns of actively exploited vulnerabilities in Exchange ServerCisco Talos·Sep 30, 21:16 UTC · Sep 30, 2022Vulnerability in the wildCVE-2022-41040CVE-2022-4108260
Hackers Are Targeting Microsoft Exchange Servers With RansomwareThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2021Ransomware in the wild60
NSA says it found new critical vulnerabilities in Microsoft Exchange ServerCyberScoop·Apr 13, 19:37 UTC · Apr 13, 2021Vulnerability in the wild60
Critical Exchange Server Flaw (CVE-2024The Hacker News·Feb 17, 07:27 UTC · Feb 17, 2024Exploit / PoC in the wildCVE-2024-21410CVE-2024-21351CVE-2024-21412+1 CVEs160
Microsoft Issues Patches for Actively Exploited Excel, Exchange Server 0The Hacker News·Nov 10, 06:24 UTC · Nov 10, 2021Vulnerability in the wildCVE-2021-42321CVE-2021-42292CVE-2021-43208+16 CVEs160
Amid widespread Exchange Server attacks, Microsoft issues patch for older versionsCyberScoop·Mar 9, 14:55 UTC · Mar 9, 2021Vulnerability in the wild60
Threat Advisory: HAFNIUM and Microsoft Exchange zeroCisco Talos·Mar 4, 15:58 UTC · Mar 4, 2021Advisory in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+5 CVEs160
CISA, Microsoft warn organizations of high-severity Microsoft Exchange vulnerabilityCyberScoop·Aug 7, 15:36 UTC · Aug 7, 2025Vulnerability in the wildCVE-2025-53786160
Microsoft One-Click Tool Mitigates Exchange Server AttacksInfosecurity Magazine·Mar 16, 10:33 UTC · Mar 16, 2021Ransomware in the wildCVE-2021-2685560
Microsoft Expands Coverage for Exchange Server BugsInfosecurity Magazine·Mar 10, 09:38 UTC · Mar 10, 2021Exploit / PoC in the wildCVE-2021-26411CVE-2021-27077CVE-2020-0792+4 CVEs60
Zero-day vulnerabilities in Microsoft Exchange ServerKaspersky Securelist·Mar 4, 17:20 UTC · Mar 4, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Microsoft Patch Tuesday follows SharePoint attacks, Exchange server warningsCyberScoop·Aug 12, 20:21 UTC · Aug 12, 2025Vulnerability in the wildCVE-2025-53786CVE-2025-53770CVE-2025-53771+8 CVEs60
No signs yet of Exchange Server compromises at federal agencies, CISA saysCyberScoop·Mar 10, 20:08 UTC · Mar 10, 2021Ransomware in the wild60
Microsoft confirms two Exchange Server zero days are being used in cyberattacksThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Exploit / PoC in the wildCVE-2022-41040CVE-2022-41082160
CISA recommends immediately patch Exchange ProxyShell flawsSecurity Affairs·Aug 23, 20:22 UTC · Aug 23, 2021Vulnerability in the wildCVE-2021-34473CVE-2021-34523CVE-2021-3120760
Actively exploited MS Exchange flaw present on 80% of exposed serversHelp Net Security·Apr 8, 00:00 UTC · Apr 8, 2020Exploit / PoC in the wildCVE-2020-068860