CVE-2021-26855 — exploited in the wild
Exploitation observed by OffSeq honeypot sensors · last 30 days · last seen 2 hours ago · first observed 2026-08-10 (30 days ago)
1,890
Exploitation attempts
62
Distinct source IPs
1
Exposed hosts
9.1
CVSS
100.0%
EPSS
KEV
CISA Known-Exploited
Listed in CISA's Known Exploited Vulnerabilities catalog and still under active attack against OffSeq honeypot decoys.
About CVE-2021-26855
Microsoft Exchange Server Remote Code Execution Vulnerability
CWE-918
OffSeq's global honeypot fleet recorded 1,890 exploitation attempts against CVE-2021-26855 from 62 distinct source IPs in the last 30 days — direct in-the-wild telemetry: every hit is a real attacker probing a decoy, not a scan of a vulnerability database. It is also present on 1 internet-exposed hosts OffSeq tracked in the last 30 days.
Top attacking countries
- Germany715
- United States339
- Canada283
- United Kingdom261
- The Netherlands204
- Singapore69
- India19