References https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855 https://nvd.nist.gov/vuln/detail/CVE-2021-26855 https://proxylogon.com/ https://www.upguard.com/blog/cve-2021-26855 https://www.sentinelone.com/vulnerability-database/cve-2021-26855/ https://msrc.microsoft.com/update-guide/en-US/security-guidance/advisory/CVE-2021-26855 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26855 https://www.tenable.com/blog/cve-2021-26855-cve-2021-26857-cve-2021-26858-cve-2021-27065-four-microsoft-exchange-server-zero-day-vulnerabilities https://unit42.paloaltonetworks.com/remediation-steps-for-the-microsoft-exchange-server-vulnerabilities/ https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-26855.yaml
Related Vulnerabilities广联达OA /GB/LK/Document/DataExchange/DataExchange.ashx XML 外部实体注入漏洞PoCspringboot-httpexchanges: Detects Springboot HTTP Exchanges ActuatorPoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)飞企互联-FE企业运营管理平台 /docexchangeManage/checkGroupCode.jsp;.js SQL 注入漏洞PoCCVE-2008-1547: Microsoft OWA Exchange Server 2003 - 'redir.asp' Open RedirectionPoCCVE-2021-26855: Microsoft Exchange Server SSRF VulnerabilityPoCCVE-2021-31195: Microsoft Exchange Server - Cross-Site ScriptingPoCCVE-2021-34473: Exchange Server - Remote Code ExecutionPoCCVE-2021-41349: Microsoft Exchange Server Pre-Auth POST Based Cross-Site ScriptingPoCCVE-2021-26855: Microsoft Exchange Server Remote Code ExecutionPoCCVE-2021-41349: Microsoft Exchange Server Pre-Auth POST Based Reflected Cross-Site Scripting