CVE-2021-26854: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.00.1497.012Patch KB5000871 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.0721.013Patch KB5000871 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.0792.010Patch KB5000871 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2106.013Patch KB5000871 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2176.009Patch KB5000871
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26854?
CVE-2021-26854 is rated as critical due to its potential for remote code execution.
How do I fix CVE-2021-26854?
To mitigate CVE-2021-26854, apply the latest security update for your version of Microsoft Exchange Server.
What versions of Microsoft Exchange Server are affected by CVE-2021-26854?
CVE-2021-26854 affects Microsoft Exchange Server 2013, 2016, and 2019 in specific cumulative updates.
What kind of attacks can exploit CVE-2021-26854?
CVE-2021-26854 can be exploited remotely to execute arbitrary code on the affected server.
Is there a workaround for CVE-2021-26854?
There is no recommended workaround for CVE-2021-26854; the only solution is to apply the security updates.