First published: Tue Mar 02 2021(Updated: )
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2013-cumulative_update_21 | |
Microsoft Exchange Server | =2013-cumulative_update_22 | |
Microsoft Exchange Server | =2013-cumulative_update_23 | |
Microsoft Exchange Server | =2016-cumulative_update_10 | |
Microsoft Exchange Server | =2016-cumulative_update_11 | |
Microsoft Exchange Server | =2016-cumulative_update_12 | |
Microsoft Exchange Server | =2016-cumulative_update_13 | |
Microsoft Exchange Server | =2016-cumulative_update_14 | |
Microsoft Exchange Server | =2016-cumulative_update_15 | |
Microsoft Exchange Server | =2016-cumulative_update_16 | |
Microsoft Exchange Server | =2016-cumulative_update_17 | |
Microsoft Exchange Server | =2016-cumulative_update_18 | |
Microsoft Exchange Server | =2016-cumulative_update_19 | |
Microsoft Exchange Server | =2016-cumulative_update_8 | |
Microsoft Exchange Server | =2016-cumulative_update_9 | |
Microsoft Exchange Server | =2019 | |
Microsoft Exchange Server | =2019-cumulative_update_1 | |
Microsoft Exchange Server | =2019-cumulative_update_2 | |
Microsoft Exchange Server | =2019-cumulative_update_3 | |
Microsoft Exchange Server | =2019-cumulative_update_4 | |
Microsoft Exchange Server | =2019-cumulative_update_5 | |
Microsoft Exchange Server | =2019-cumulative_update_6 | |
Microsoft Exchange Server | =2019-cumulative_update_7 | |
Microsoft Exchange Server | =2019-cumulative_update_8 | |
Microsoft Exchange Server | ||
=2013-cumulative_update_21 | ||
=2013-cumulative_update_22 | ||
=2013-cumulative_update_23 | ||
=2016-cumulative_update_10 | ||
=2016-cumulative_update_11 | ||
=2016-cumulative_update_12 | ||
=2016-cumulative_update_13 | ||
=2016-cumulative_update_14 | ||
=2016-cumulative_update_15 | ||
=2016-cumulative_update_16 | ||
=2016-cumulative_update_17 | ||
=2016-cumulative_update_18 | ||
=2016-cumulative_update_19 | ||
=2016-cumulative_update_8 | ||
=2016-cumulative_update_9 | ||
=2019 | ||
=2019-cumulative_update_1 | ||
=2019-cumulative_update_2 | ||
=2019-cumulative_update_3 | ||
=2019-cumulative_update_4 | ||
=2019-cumulative_update_5 | ||
=2019-cumulative_update_6 | ||
=2019-cumulative_update_7 | ||
=2019-cumulative_update_8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26855 is a remote code execution vulnerability in Microsoft Exchange Server.
The severity of CVE-2021-26855 is critical, with a severity value of 9.8.
Microsoft Exchange Server versions 2013, 2016, and 2019 are affected by CVE-2021-26855.
Update your Microsoft Exchange Server to the latest cumulative update to fix CVE-2021-26855.
You can find more information about CVE-2021-26855 in the references provided: [CISA Emergency Directive 21-02](https://www.cisa.gov/emergency-directive-21-02), [Packet Storm Security](http://packetstormsecurity.com/files/161846/Microsoft-Exchange-2019-SSRF-Arbitrary-File-Write.html), [Packet Storm Security](http://packetstormsecurity.com/files/161938/Microsoft-Exchange-ProxyLogon-Remote-Code-Execution.html).