First published: Tue Mar 02 2021(Updated: )
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2013-cumulative_update_23 | |
Microsoft Exchange Server | =2016-cumulative_update_18 | |
Microsoft Exchange Server | =2016-cumulative_update_19 | |
Microsoft Exchange Server | =2019-cumulative_update_7 | |
Microsoft Exchange Server | =2019-cumulative_update_8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26412 has been rated as critical due to its potential for remote code execution.
To fix CVE-2021-26412, apply the latest security updates provided by Microsoft for your version of Exchange Server.
CVE-2021-26412 affects Microsoft Exchange Server 2013 CU23, 2016 CU18 and CU19, and 2019 CU7 and CU8.
Yes, CVE-2021-26412 can be exploited remotely without authentication, making it particularly dangerous.
Yes, there are known exploits in the wild that target CVE-2021-26412, emphasizing the urgency to apply patches.