CVE-2021-26855: Microsoft Exchange Server SSRF Vulnerability

HoneyLabs honeypots recorded 15 probes matching CVE-2021-26855 from 7 distinct source IP addresses in the last 7 days. Severity is rated critical.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /owa/auth/x.js

Addresses probing it

Source IPProbesNetworkCountry
20.84.164.1994Microsoft CorporationUnited States
130.131.161.2083Microsoft CorporationUnited States
40.119.28.1693Microsoft CorporationUnited States
40.119.43.2182Microsoft CorporationUnited States
20.169.50.1191Microsoft CorporationUnited States
20.14.73.461Microsoft CorporationUnited States
20.84.124.1491Microsoft CorporationUnited States

Networks it comes from

ASNOrganisationProbesSource IPs
AS8075Microsoft Corporation157

Captured requests

  • /owa/auth/x.js

HTTP client fingerprints (JA4H)

  • ge11cn0400_f49c2c4a715a

CVE report

CVE report

Open a specific CVE from the CVE tracker.