CRITICAL
CVE-2021-26855
CVSS
9.1
KEV
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
Summary dbcve.org
This is a Remote Code Execution vulnerability in Microsoft Exchange Server. The CVSS score of 9.1 indicates critical severity with the potential for complete system compromise without authentication.
Mitigation
Apply Microsoft security updates for Exchange Server immediately, as this vulnerability was actively exploited in the wild and enables unauthenticated attackers to execute arbitrary code.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
100%
Probability of exploitation in next 30 days
100th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855
Patch, Vendor Advisory
http://packetstormsecurity.com/files/161846/Microsoft-Exchange-2019-SSRF-Arbitrary-File-Write.html
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/161938/Microsoft-Exchange-ProxyLogon-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/162610/Microsoft-Exchange-2019-Unauthenticated-Email-Download.html
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/162736/Microsoft-Exchange-ProxyLogon-Collector.html
Exploit, Third Party Advisory, VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26855
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26855
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.