CVE-2021-26855: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Other sources
Microsoft Exchange Server Remote Code Execution Vulnerability
— NVD
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-26855?
CVE-2021-26855 is a remote code execution vulnerability in Microsoft Exchange Server.
What is the severity of CVE-2021-26855?
The severity of CVE-2021-26855 is critical, with a severity value of 9.8.
Which products are affected by CVE-2021-26855?
Microsoft Exchange Server versions 2013, 2016, and 2019 are affected by CVE-2021-26855.
How do I fix CVE-2021-26855?
Update your Microsoft Exchange Server to the latest cumulative update to fix CVE-2021-26855.
Where can I find more information about CVE-2021-26855?
You can find more information about CVE-2021-26855 in the references provided: [CISA Emergency Directive 21-02](https://www.cisa.gov/emergency-directive-21-02), [Packet Storm Security](http://packetstormsecurity.com/files/161846/Microsoft-Exchange-2019-SSRF-Arbitrary-File-Write.html), [Packet Storm Security](http://packetstormsecurity.com/files/161938/Microsoft-Exchange-ProxyLogon-Remote-Code-Execution.html).