CVE-2021-26855 - Microsoft Exchange Server Remote Code Execution Vulnerability
Project:Microsoft
Product:Exchange Server
Date Added:2021-11-03Due Date:2021-04-16
Vulnerability Name
Microsoft Exchange Server Remote Code Execution Vulnerability
Description
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply updates per vendor instructions.
Additional Notes
Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-26855
Related News Articles
Chinese Hacker Xu Zewei Arrested for Ties to Silk Typhoon Group and U.S. Cyber AttacksJuly 9, 2025
Hackers Target Over 70 Microsoft Exchange Servers to Steal Credentials via KeyloggersJune 24, 2025
US indicts Black Kingdom ransomware admin for Microsoft Exchange attacksMay 2, 2025
Kaspersky Links Head Mare to Twelve, Targeting Russian Entities via Shared C2 ServersMarch 21, 2025
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [27 January]January 27, 2025