CVE report
CVE-2021-26855criticalKEV
Microsoft Exchange Server SSRF Vulnerability
Events 90d
109
Distinct IPs
14
Severity
critical
CISA KEV
Actively exploited
Detection signature
An event counts toward CVE-2021-26855 when its URL path contains any of these (case-insensitive). This is what our matching is based on.
- ยท /owa/auth/x.js
Pre-disclosure activity
all early actors โAnalysing probe history around the publication dateโฆ
Recent probe volume (last 7 days)
peak: 4 events/dayeventsdistinct IPs
Downloads & integrations
Top sources probing for CVE-2021-26855
- 135.237.127.5411 eventsUnited States
- 20.172.67.17611 eventsUnited States
- 172.203.234.25111 eventsUnited States
- 20.168.0.21810 eventsUnited States
- 20.65.193.1689 eventsUnited States
- 48.217.87.789 eventsUnited States
- 20.98.140.1809 eventsUnited States
- 172.202.117.2139 eventsUnited States
- 40.119.24.1308 eventsUnited States
- 20.169.85.1147 eventsUnited States
- 20.65.193.2037 eventsUnited States
- 20.221.71.2265 eventsUnited States
- 101.36.125.582 eventsHong Kongยท UCLOUD INFORMATION TECHNOLOGY HK LIMITED
- 31.59.160.31 eventsUnited Arab Emiratesยท Miteflux Technologies Ltd
Top networks the attempts come from
Fingerprints of the clients exploiting this
The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.
Sample request paths observed
- /owa/auth/x.js