HIGH

CVE-2021-26858

Microsoft Exchange Server 2021-03-03 CVSS v3.1
CVSS
7.8
KEV

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Summary dbcve.org

This is a server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server that allows an authenticated attacker to make the server perform arbitrary HTTP requests, potentially leading to remote code execution when chained with other vulnerabilities.

Mitigation

Apply Microsoft security updates released in March 2021 (KB5000871) to Exchange Server, or implement emergency mitigations such as blocking unauthenticated ECP/API requests at the perimeter and enabling Windows Advanced Threat Protection for Exchange.

Patch Commit

EPSS Score

93.65%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE