S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 22, 2026

CVE-2021-28480 Scanner

CVE-2021-28480 Scanner - Server-Side Request Forgery (SSRF) vulnerability in Microsoft Exchange Server

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-28480
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Microsoft Exchange Server 2013 Cumulative Update 23by Microsoft
AFFECTED< 15.00.1497.015SAFE ✓≥ 15.00.1497.015
Microsoft Exchange Server 2016 Cumulative Update 19by Microsoft
AFFECTED< 15.01.2176.012SAFE ✓≥ 15.01.2176.012
Microsoft Exchange Server 2019 Cumulative Update 8by Microsoft
AFFECTED< 15.02.0792.013SAFE ✓≥ 15.02.0792.013
Microsoft Exchange Server 2016 Cumulative Update 20by Microsoft
AFFECTED< 15.01.2242.008SAFE ✓≥ 15.01.2242.008
Updated Aug 21, 2026View on NVD →
Detail

Microsoft Exchange Server is widely used by organizations to facilitate email communication, calendaring, and collaboration. It is deployed across many enterprise environments and can be hosted on servers in data centers or on cloud platforms. Exchange Server is primarily used by IT administrators, system administrators, and network engineers to manage emails and user information. It integrates with Active Directory for user authentication and supports multiple protocols like SMTP, IMAP, and MAPI. Exchange Server is also used for archiving and ensuring data compliance in professional settings.

The Server-Side Request Forgery (SSRF) vulnerability in Microsoft Exchange Server enables attackers to manipulate a server application to make unauthorized requests to arbitrary domains. This type of vulnerability can lead to unauthorized access to sensitive data and system takeover. Attackers might exploit SSRF to scan internal networks, extract system information, and leverage other vulnerabilities present in infrastructure. Since the vulnerability bypasses traditional security protocols, it is a significant threat to the integrity of the organization's IT environment.

The vulnerable endpoint in this SSRF vulnerability involves the misuse of the 'OWA' component in Exchange Server where improper validation of header data allows an attacker to craft malicious requests. Attackers inject an 'X-BackEndCookie' header with crafted data to the server, which leads to undesirable actions being executed. The vulnerable parameter typically involves headers used in HTTP requests, and the technique involves XOR-encoding values to mask and alter data sent to the server. This vulnerability presents a vector for critical exploitation if unpatched and accessible.

If this vulnerability is exploited, malicious entities could compromise the entire server infrastructure that hosts Exchange Server. This could lead to unauthorized data access, data manipulation, and potential data breaches. Attackers might orchestrate lateral attacks, jumping from the Exchange Server to other internal services, leading to broader systems compromise. Additionally, attackers could exploit this to deploy ransomware or steal encrypted data for further attack campaigns.

REFERENCES

Solution Advice
  • Apply the latest security patches and updates provided by Microsoft for Exchange Server.
  • Regularly monitor and analyze incoming requests to detect and mitigate potential SSRF attacks.
  • Implement robust network segmentation to limit the impact of unauthorized requests.
  • Enhance server-side input validation to prevent exploitation through crafted requests.
  • Restrict external server communication to essential services only, minimizing exposure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.