PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Network Vulnerabilities·Updated Feb 22, 2026

Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3.4k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-28480
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Microsoft Exchange Server 2013 Cumulative Update 23by Microsoft
AFFECTED< 15.00.1497.015SAFE ✓≥ 15.00.1497.015
Microsoft Exchange Server 2016 Cumulative Update 19by Microsoft
AFFECTED< 15.01.2176.012SAFE ✓≥ 15.01.2176.012
Microsoft Exchange Server 2019 Cumulative Update 8by Microsoft
AFFECTED< 15.02.0792.013SAFE ✓≥ 15.02.0792.013
Microsoft Exchange Server 2016 Cumulative Update 20by Microsoft
AFFECTED< 15.01.2242.008SAFE ✓≥ 15.01.2242.008
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound) CVE-2021-28480 Scanner | S4E