LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-26855: Microsoft Exchange Server Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
CVSS 9.1 · Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
9.1
CVSS score
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-26855 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-26855 is a remote code execution vulnerability in Microsoft Exchange Server. It is part of the ProxyLogon exploit chain and has been used by ransomware operators. Organizations running Exchange should treat this as a high-priority issue because successful abuse can give an attacker a foothold on the mail server and a path deeper into the environment.

Public detail on exact mechanics is limited beyond the CWE and CISA description; confirm all version, configuration, and patch specifics against the Microsoft vendor advisory before acting.

How it works

The weakness is classified as CWE-918 (Server-Side Request Forgery). In this class of flaw, the server can be tricked into making requests that the attacker controls or influences. When chained as part of ProxyLogon, the SSRF step helps an unauthenticated or low-privilege attacker reach internal Exchange components that should not be directly exposed, ultimately enabling remote code execution on the server.

An attacker typically sends crafted requests to the Exchange front-end so that the server itself performs actions or reaches endpoints on the attacker’s behalf. Because Exchange often holds privileged access to mailboxes, Active Directory, and internal networks, code execution on the server can lead to data theft, persistence, lateral movement, or deployment of ransomware. Exact request formats and exploit steps are not detailed here; treat any public proof-of-concept material with caution and validate behavior only in isolated lab conditions against the official advisory.

Am I affected? How to find it in your systems

Microsoft Exchange Server is commonly deployed on-premises or in hybrid configurations to provide corporate email, calendaring, and collaboration. It usually runs on Windows Server and is reachable via HTTPS on ports 443 (and sometimes 80) from internal clients and, if internet-facing, from the outside.

How to remediate

The primary remediation is to apply the security updates Microsoft released for this vulnerability, following the vendor’s installation order and prerequisites exactly. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

If immediate patching is blocked by operational constraints, apply compensating controls while you schedule the update.

These measures reduce risk but do not replace the vendor patch. Schedule the official update as the definitive fix.

If your data may have been exposed

This vulnerability has been actively exploited and is known to have been used by ransomware actors. If your Exchange servers were unpatched and reachable during the period of exploitation, assume possible compromise: isolate affected hosts, collect memory and disk images, hunt for webshells or unexpected persistence, reset privileged credentials, and engage incident-response procedures. Review mail-flow and authentication logs for signs of data access or exfiltration.

As an additional check for personal or corporate email addresses that may appear in known breach data sets, you can run a free exposure scan of your email to see whether those addresses have already surfaced in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Exchange Server
WeaknessCWE-918
CVSS base score9.1 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
PublishedMar 3, 2021
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities