Known exploited / historically exploited security risk
CVE-2021-31207 — Microsoft Exchange Server
A Microsoft Exchange Server security feature bypass vulnerability associated with ProxyShell exploitation and included in CISA's exploited-vulnerability guidance.
Business relevance
If Microsoft Exchange Server is present in your environment, confirm whether the installed version and configuration are affected. The existence of this CVE does not by itself prove that a specific system is vulnerable or compromised.
What to check
- Identify on-premises Exchange Server systems.
- Confirm exact Exchange version and patch level.
- Verify applicable Microsoft security updates.
- Review exposure and incident indicators if the system was previously unpatched.
Source record
Authoritative source: CISA ProxyShell guidance and routinely exploited vulnerabilities advisory.
CompFlorida record reviewed: September 21, 2026.
Vendor: Microsoft
Product: Microsoft Exchange Server
CVE: CVE-2021-31207
Need help checking applicability?
CompFlorida can help identify the product/version in use, review exposure and coordinate the appropriate remediation path.
Request a Technology Risk Review
