CVE-2021-26855
Sfruttamento noto · CISA KEV
CVSS 9.1 CRITICAL: microsoft Exchange Server Remote Code Execution Vulnerability Impiego noto in campagne ransomware. EPSS 100% (100º percentile).
Data di correzione federale CISA 3 mag · data superata
Minacce · 148 giorni fa
Unpatched Exchange and IIS servers are being used as long-term footholds, not just entry points. The standard response of fixing the server misses the bigger problem: once ShadowPad lands, the actor can stay inside for surveillance across government, defense, media, and critical infrastructure networks.
Trend Micro attributes the activity to Shadow-Earth-053, a China-aligned cluster active since at least December 2024. The campaign uses known Microsoft Exchange and IIS flaws — CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 — and has reached organizations across South, East, and Southeast Asia, with spillover into at least one NATO member state.
The targeting of journalists and civil society activists points to collection and influence goals, not simple theft. Persistent ShadowPad implants mean the risk continues after initial access is closed, because the operator is built for staying power and monitoring.
Sfruttamento noto · CISA KEV
CVSS 9.1 CRITICAL: microsoft Exchange Server Remote Code Execution Vulnerability Impiego noto in campagne ransomware. EPSS 100% (100º percentile).
Data di correzione federale CISA 3 mag · data superata
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: microsoft Exchange Server Remote Code Execution Vulnerability Impiego noto in campagne ransomware. EPSS 100% (100º percentile).
Data di correzione federale CISA 3 mag · data superata
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: microsoft Exchange Server Remote Code Execution Vulnerability Impiego noto in campagne ransomware. EPSS 96% (100º percentile).
Data di correzione federale CISA 3 mag · data superata
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: microsoft Exchange Server Remote Code Execution Vulnerability Impiego noto in campagne ransomware. EPSS 94% (100º percentile).
Data di correzione federale CISA 3 mag · data superata
1 fonte che coprono questa storia
Trend Micro details Shadow-Earth-053 targeting Asian government, defense, critical infrastructure via Exchange and IIS vulnerabilities.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-05-05