EXPOSURES › CVE-2021-26855
CVE-2021-26855
CRITICAL ⌖ ON CISA KEV · EXPLOITEDMicrosoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.
CVE-2021-26855, part of the ProxyLogon exploit chain, allowed remote code execution on vulnerable Microsoft Exchange Servers. DIB organizations using unpatched Exchange Servers faced significant exposure to ransomware and data breaches, impacting CMMC compliance. Immediate patching and version upgrades are critical.
Shame score — Systemic validation failures leading to widespread, actively exploited RCE demonstrate significant negligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
"Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |