MIRAGE
Threat IntelligenceCVEs › CVE-2021-26855

CVE-2021-26855 — exploited in the wild

Exploitation observed by OffSeq honeypot sensors · last 30 days · last seen 2 hours ago · first observed 2026-08-10 (30 days ago)

1,890
Exploitation attempts
62
Distinct source IPs
1
Exposed hosts
9.1
CVSS
100.0%
EPSS
KEV
CISA Known-Exploited

Listed in CISA's Known Exploited Vulnerabilities catalog and still under active attack against OffSeq honeypot decoys.

About CVE-2021-26855

Microsoft Exchange Server Remote Code Execution Vulnerability

CWE-918

OffSeq's global honeypot fleet recorded 1,890 exploitation attempts against CVE-2021-26855 from 62 distinct source IPs in the last 30 days — direct in-the-wild telemetry: every hit is a real attacker probing a decoy, not a scan of a vulnerability database. It is also present on 1 internet-exposed hosts OffSeq tracked in the last 30 days.

Top attacking countries

Top attacking networks

Techniques observed

Open the live CVE-2021-26855 view →

References