References https://www.fortinet.com/blog/threat-research/microsoft-exchange-zero-day-vulnerability-updates https://www.sentinelone.com/vulnerability-database/cve-2022-41082/ https://www.picussecurity.com/resource/blog/proxynotshellcve-2022-41040-and-cve-2022-41082-exploits-explained https://www.kb.cert.org/vuls/id/915563 https://www.secrss.com/articles/47582 https://www.cc.ntu.edu.tw/chinese/cert/cert20221012.asp https://research.splunk.com/web/d436f9e7-0ee7-4a47-864b-6dea2c4e2752/ https://www.blumira.com/blog/zero-day-vulnerabilities-found-in-microsoft-exchange https://support.microsoft.com/en-us/topic/description-of-security-update-1-for-exchange-server-2019-march-12-2024-kb5036401-9160baeb-6306-4384-a5c9-94b0a18cba8e https://www.geekby.site/2021/10/exchange%E7%9B%B8%E5%85%B3%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0/ https://www.fortiguard.com/encyclopedia/ips/50584 https://www.reddit.com/r/msp/comments/zt04qb/critical_vulnerability_microsoft_exchange_remote/
Related VulnerabilitiesPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)广联达OA /GB/LK/Document/DataExchange/DataExchange.ashx XML 外部实体注入漏洞PoCspringboot-httpexchanges: Detects Springboot HTTP Exchanges ActuatorPoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCsharepoint-lists-api-disclosure: Microsoft SharePoint - List API DisclosurePoCsharepoint-layouts-disclosure: Microsoft SharePoint - Layouts DisclosurePoCsharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page DisclosurePoCsharepoint-site-metadata-disclosure: Microsoft SharePoint - Site Metadata DisclosurePoCsharepoint-sitepages-disclosure: Microsoft SharePoint - Site Pages Disclosure