HIGH
CVE-2021-26858
CVSS
7.8
KEV
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
Summary dbcve.org
This is a server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server that allows an authenticated attacker to make the server perform arbitrary HTTP requests, potentially leading to remote code execution when chained with other vulnerabilities.
Mitigation
Apply Microsoft security updates released in March 2021 (KB5000871) to Exchange Server, or implement emergency mitigations such as blocking unauthenticated ECP/API requests at the perimeter and enabling Windows Advanced Threat Protection for Exchange.
EPSS Score
93.65%
Probability of exploitation in next 30 days
99.8th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26858
Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26858
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26858
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.