CVE-2021-26855
Sfruttamento noto · CISA KEV
CVSS 9.1 CRITICAL: microsoft Exchange Server Remote Code Execution Vulnerability Impiego noto in campagne ransomware. EPSS 100% (100º percentile).
Data di correzione federale CISA 3 mag · data superata
Minacce e avversari · Spionaggio APT
Unpatched Exchange and IIS servers are being used as long-term footholds, not just entry points. The standard response of fixing the server misses the bigger problem: once ShadowPad lands, the actor can stay inside for surveillance across government, defense, media, and critical infrastructure networks.
Trend Micro attributes the activity to Shadow-Earth-053, a China-aligned cluster active since at least December 2024. The campaign uses known Microsoft Exchange and IIS flaws — CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 — and has reached organizations across South, East, and Southeast Asia, with spillover into at least one NATO member state.
The targeting of journalists and civil society activists points to collection and influence goals, not simple theft. Persistent ShadowPad implants mean the risk continues after initial access is closed, because the operator is built for staying power and monitoring.
1 fonte · 4 mag
Sfruttamento noto · CISA KEV
CVSS 9.1 CRITICAL: microsoft Exchange Server Remote Code Execution Vulnerability Impiego noto in campagne ransomware. EPSS 100% (100º percentile).
Data di correzione federale CISA 3 mag · data superata
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: microsoft Exchange Server Remote Code Execution Vulnerability Impiego noto in campagne ransomware. EPSS 100% (100º percentile).
Data di correzione federale CISA 3 mag · data superata
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: microsoft Exchange Server Remote Code Execution Vulnerability Impiego noto in campagne ransomware. EPSS 96% (100º percentile).
Data di correzione federale CISA 3 mag · data superata
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: microsoft Exchange Server Remote Code Execution Vulnerability Impiego noto in campagne ransomware. EPSS 94% (100º percentile).
Data di correzione federale CISA 3 mag · data superata
Industrial Cyber
Shadow-Earth-053 targets Asian government, defense, critical infrastructure via Exchange and IIS vulnerabilities - Industrial Cyber
Trend Micro details Shadow-Earth-053 targeting Asian government, defense, critical infrastructure via Exchange and IIS vulnerabilities.
originaleRiepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-05-05
Every edition of this story: ShadowPad Espionage Campaign Targets Exchange and IIS Servers