CRITICAL

CVE-2021-26855

Microsoft Exchange Server 2021-03-03 CVSS v3.1
CVSS
9.1
KEV

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Summary dbcve.org

This is a Remote Code Execution vulnerability in Microsoft Exchange Server. The CVSS score of 9.1 indicates critical severity with the potential for complete system compromise without authentication.

Mitigation

Apply Microsoft security updates for Exchange Server immediately, as this vulnerability was actively exploited in the wild and enables unauthenticated attackers to execute arbitrary code.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

100%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE