CVE-2021-26855: Microsoft Exchange Server SSRF Vulnerability
HoneyLabs honeypots recorded 15 probes matching CVE-2021-26855 from 7 distinct source IP addresses in the last 7 days. Severity is rated critical.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /owa/auth/x.js
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 20.84.164.199 | 4 | Microsoft Corporation | United States |
| 130.131.161.208 | 3 | Microsoft Corporation | United States |
| 40.119.28.169 | 3 | Microsoft Corporation | United States |
| 40.119.43.218 | 2 | Microsoft Corporation | United States |
| 20.169.50.119 | 1 | Microsoft Corporation | United States |
| 20.14.73.46 | 1 | Microsoft Corporation | United States |
| 20.84.124.149 | 1 | Microsoft Corporation | United States |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS8075 | Microsoft Corporation | 15 | 7 |
Captured requests
- /owa/auth/x.js
HTTP client fingerprints (JA4H)
- ge11cn0400_f49c2c4a715a
CVE report
CVE report
Open a specific CVE from the CVE tracker.