CVE-2021-26855
Known exploited · CISA KEV
CVSS 9.1 CRITICAL: microsoft Exchange Server Remote Code Execution Vulnerability Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date May 3 · date passed
Threats & Adversaries · APT / Espionage
Unpatched Exchange and IIS servers are being used as long-term footholds, not just entry points. The standard response of fixing the server misses the bigger problem: once ShadowPad lands, the actor can stay inside for surveillance across government, defense, media, and critical infrastructure networks.
Trend Micro attributes the activity to Shadow-Earth-053, a China-aligned cluster active since at least December 2024. The campaign uses known Microsoft Exchange and IIS flaws — CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 — and has reached organizations across South, East, and Southeast Asia, with spillover into at least one NATO member state.
The targeting of journalists and civil society activists points to collection and influence goals, not simple theft. Persistent ShadowPad implants mean the risk continues after initial access is closed, because the operator is built for staying power and monitoring.
1 source · May 4
Known exploited · CISA KEV
CVSS 9.1 CRITICAL: microsoft Exchange Server Remote Code Execution Vulnerability Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date May 3 · date passed
Known exploited · CISA KEV
CVSS 7.8 HIGH: microsoft Exchange Server Remote Code Execution Vulnerability Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date May 3 · date passed
Known exploited · CISA KEV
CVSS 7.8 HIGH: microsoft Exchange Server Remote Code Execution Vulnerability Known ransomware campaign use. EPSS 96% (100th percentile).
CISA federal remediation date May 3 · date passed
Known exploited · CISA KEV
CVSS 7.8 HIGH: microsoft Exchange Server Remote Code Execution Vulnerability Known ransomware campaign use. EPSS 94% (100th percentile).
CISA federal remediation date May 3 · date passed
Industrial Cyber
Shadow-Earth-053 targets Asian government, defense, critical infrastructure via Exchange and IIS vulnerabilities - Industrial Cyber
Trend Micro details Shadow-Earth-053 targeting Asian government, defense, critical infrastructure via Exchange and IIS vulnerabilities.
originalPart of the PlainSec briefing for 2026-05-04
Every edition of this story: ShadowPad Espionage Campaign Targets Exchange and IIS Servers