← Back to all briefings
Cybersecurity 5 min read Published Updated Credibility 40/100

Cybersecurity Briefing — Microsoft Exchange zero-days exploited by Hafnium

Microsoft disclosed on 2 March 2021 that four Exchange Server zero-days were being exploited by Hafnium, prompting out-of-band patches and global emergency response for on-prem email servers.

Single-point timeline showing the publication date sized by credibility score.
Publication date and credibility emphasis for this briefing. Source data (JSON)

On 2 March 2021 Microsoft released out-of-band fixes for four Exchange Server vulnerabilities (including CVE-2021-26855) under active exploitation by the Hafnium threat group. Mass exploitation led to widespread web shell installation, requiring rapid patching and forensic triage.

Security teams should inventory on-prem Exchange instances, apply cumulative updates, hunt for web shells and Indicators of Compromise from Microsoft guidance, and isolate compromised servers while enabling EDR coverage.

Single-point timeline showing the publication date sized by credibility score.
Publication date and credibility emphasis for this briefing. Source data (JSON)

Continue in the Cybersecurity pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

  • Exchange Server
  • zero-day
  • Hafnium
  • incident response
Back to curated briefings