Vulnerability threat dossier

CVE-2021-26855

microsoftexchange server

Microsoft Exchange Server Remote Code Execution Vulnerability

VTP deterministic threat54.5of 100 · CVSS excluded

VTP analyst assessment

Microsoft Exchange Server remote code execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence93%
Public exploitation · VTP factKEV

Assessment

CISA KEV lists this Exchange Server vulnerability as exploited globally. It can enable remote code execution on affected Exchange Server installations.

Why it matters

  • Exchange servers process organizational email and often hold high-value data.
  • CISA KEV records known ransomware campaign use.

Evidence

1 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

A recent press item is not relevant to this CVE and does not establish current exploitation.

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

Next watchpoint

If you run affected Exchange Server releases, apply Microsoft remediation and restrict unnecessary external access.

AI baseline history (4)
  1. BASELINE ASSESSED
    Microsoft Exchange Server remote code executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    Microsoft Exchange Server remote code executiongpt-5.6-terra · low
  3. BASELINE ASSESSED
    Microsoft Exchange Server remote code executiongpt-5.6-terra · low
  4. BASELINE ASSESSED
    Microsoft Exchange Server remote code executiongpt-5.6-sol · high
Technical severityCRITICALCVSS 9.1 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence64%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Availability: SENSOR_ONLINE_ACTIVITY_OBSERVED · Evidence: CVE_LIKE_ATTEMPT
LOW

The request shares exploitation-associated characteristics with CVE-2021-26855, but the evidence does not identify one CVE with sufficient confidence.

CANDIDATE LEADTechnical consistency 35/100

Basis: deterministic technical candidate

Potentially consistent; exploitation not confirmedDisclosure embargo completed
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  3. 03

    Exploitation attempts against this CVE were confirmed by first-party telemetry.

  4. 04

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

0 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:a3245ac22fbdfa682646d4fa3328850e649e7d6f999276e27ad1da895c6cdfd9ACTIVE
Evidence
04

Event history

Threat timeline

  1. 16:4226 Aug
    ZERO DAY

    Zero Day

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 00:0003 Nov
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.

CVE-2019-0708CVE-2020-0688CVE-2021-26855CVE-2026-42897
Separate evidence group
Original

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&

CVE-2018-13379CVE-2019-10068CVE-2019-19781CVE-2020-5902CVE-2021-26855CVE-2021-44228CVE-2023-22515CVE-2024-24919CVE-2024-8190CVE-2024-8963CVE-2024-9380CVE-2025-31161CVE-2026-1731
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score54.5vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction20 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE
CWE-918
CPE records
24
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.