CVE-2021-27076
published 2021-03-11CVE-2021-27076: Microsoft SharePoint Server Remote Code Execution Vulnerability
PriorityP181high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
14.39%
96.2th percentile
Microsoft SharePoint Server Remote Code Execution Vulnerability
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | business_productivity_servers | — | — |
| microsoft | microsoft_business_productivity_servers_2010_service_pack_2 | >= 13.0.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_foundation_2013_service_pack_1 | >= 15.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < publication | publication |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_business_productivity_servers_2010_service_pack_2 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandSchtasks /create /ru "SYSTEM" /tn "\Microsoft\Windows\Edge\Edgeupdates" /sc DAILY /tr "C:\ProgramData\SystemSettings.exe" /F↗
- →SettingSyncHost.exe running from a non-standard path (e.g., C:\Program Files\Chiniks\) instead of C:\Windows\System32\ or C:\Windows\SysWOW64\ indicates DLL sideloading abuse. ↗
- ·The attacker attributed to ToddyCat APT; exploitation requires the attacker to have privileges to create a site on the SharePoint server (not unauthenticated). ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v4x2-cq4f-rv9r: Microsoft SharePoint Server Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-27076 [HIGH] GHSA-v4x2-cq4f-rv9r: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
VulnCheck
Microsoft business_productivity_servers Vulnerability
vulncheck·2021·CVSS 8.8
CVE-2021-27076 [HIGH] Microsoft business_productivity_servers Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Affected: Microsoft business_productivity_servers
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://securelist.com/strikeshark-campaign/120326/
Microsoft
Microsoft SharePoint Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 8.8
CVE-2021-27076 [HIGH] Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
FAQ: What is the attack vector for this vulnerability?
In a network-based attack an attacker could gain access to create a site and could execute code remotely. The attacker would need to have privileges.
Microsoft Office SharePoint: Microsoft Office SharePoint
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=35544dda-5748-488f-ba0a-3cb0598bd49c
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=93aae8bc-8253-4df6-a1cf-7554eb0f8eda
Reference: https://support.microsoft.com/help/4
No detection rules found.
No public exploits indexed.
Recorded Future
June 2026 CVE Landscape
blogs_recorded_future·2026-07-10·CVSS 9.1
CVE-2026-35616 [CRITICAL] June 2026 CVE Landscape
## June 2026 CVE Landscape
In June 2026, Insikt Group® identified 60 high-impact vulnerabilities that should be prioritized for remediation , 30 of which had a Very Critical Recorded Future Risk Score. This represents a 49% increase from last month. 23 of the 60 vulnerabilities were included in the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 34 were reported by vendors, and three were primarily surfaced through honeypot data.
The 60 vulnerabilities in this report affected products from 36 vendors, with Microsoft accounting for approximately 18% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform
Hackernews
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
blogs_hackernews·2026-06-26·CVSS 9.8
CVE-2021-26855 [CRITICAL] New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts.
Kaspersky, which is tracking the activity under the moniker StrikeShark , said the campaign has targeted a diplomatic organization in Indonesia, government organizations in Taiwan, software development companies across multiple countries, and entities associated with other sectors located in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Ne
Securelist
StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
blogs_securelist·2026-06-24
CVE-2021-26855 StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
Fareed Radzi
Table of Contents
Introduction
Initial infection
Exploitation of public-facing applications
Dropper-based distribution
SharkLoader installation
SharkLoader DLL – Main implant
“PerfectDLL Hijacking” technique
Decryption and loading of >DscCoreR.mui
DscCoreR.mui and SyncRes.dat DLLs
Decryption and loading of SyncRes.dat
SyncRes.dat decrypted DLL: Multiple API hooks
VEH registration and access violation handling
Thread creation for Cobalt Strike Beacon execution
MinHook DLL, API hooking, and Cobalt Strike beacon
Persistence mechanism
Post-compromise activity
Victimology
Attribution
Conclusion
Indicators of compromise
Authors
Fareed Radzi
## Introduction
During our research of activity affecting a diplomatic organization in Indonesia, we uncovered a previo
Securelist
Detecting DLL hijacking with machine learning: real-world cases
blogs_securelist·2025-10-06
Detecting DLL hijacking with machine learning: real-world cases
Table of Contents
Introduction
How the model works in Kaspersky SIEM
Incidents detected during the pilot testing of the model in the MDR service
Incident 1. ToddyCat trying to launch Cobalt Strike disguised as a system library
Incident 2. Infostealer masquerading as a policy manager
Incident 3. Malicious loader posing as a security solution
Conclusion
IoC
Authors
Gleb Ivanov
Andrey Gunkin
## Introduction
Our colleagues from the AI expertise center recently developed a machine-learning model that detects DLL-hijacking attacks. We then integrated this model into the Kaspersky Unified Monitoring and Analysis Platform SIEM system. In a separate article , our colleagues shared how the model had been created and what success they had achieved in lab environments. Here, we focus on h
Securelist
How a machine-learning model in Kaspersky SIEM detected DLL-hijacking incidents
blogs_securelist·2025-10-06
How a machine-learning model in Kaspersky SIEM detected DLL-hijacking incidents
Table of Contents
- Introduction
- How the model works in Kaspersky SIEM
- Incidents detected during the pilot testing of the model in the MDR service
- Conclusion
- IoC
Authors
- Gleb Ivanov
- Andrey Gunkin
## Introduction
Our colleagues from the AI expertise center recently developed a machine-learning model that detects DLL-hijacking attacks. We then integrated this model into the Kaspersky Unified Monitoring and Analysis Platform SIEM system. In a separate article, our colleagues shared how the model had been created and what success they had achieved in lab environments. Here, we focus on how it operates within Kaspersky SIEM, the preparation steps taken before its release, and some real-world incidents it has already helped us uncover.
## How the model works in Kaspersky SIEM
Trendmicro
March Patch Tuesday: Fixes for Exchange Server, IE
blogs_trendmicro·2021-03-10·CVSS 9.1
[CRITICAL] March Patch Tuesday: Fixes for Exchange Server, IE
# March Patch Tuesday: Fixes for Exchange Server, IE
This month’s Patch Tuesday includes fixes already released for the Microsoft Exchange Server zero-day flaws attributed to Hafnium attacks.
By: Trend Micro
2021/03/10
Read time: ( words)
Save to Folio
This month’s Patch Tuesday features close to a hundred fixes, almost doubling last month’s total. The list includes patches already released for the Microsoft Exchange Server zero-day flaws attributed to Hafnium attacks.
Out of 89 patches released, 14 were rated Critical while the rest were deemed Important. Most of the critical vulnerabilities involve remote code execution (RCE) link except for an information disclosure bug. Fifteen of these were reported by the Zero Day Initiative (ZDI).
Microsoft Exchange Server Vulnerabilities
Th
2021-03-11
Published
Exploited in the wild