EXPOSURES › CVE-2021-26857
CVE-2021-26857
CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
ransomwarerceexploited-in-wildunpatched
CVE-2021-26857: Microsoft Exchange Server RCE exploited in wild
CVE-2021-26857, a critical Exchange Server RCE flaw, was actively exploited, impacting unpatched versions.
Shame score — Active exploitation of a remote code execution vulnerability in a widely-used email server product.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.60
Microsoft faced severe fallout due to the ProxyLogon exploit chain, with the vulnerability allowing remote code execution in Exchange Server, leading to widespread condemnation and urgent patching dem
severe-fallout
"Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain."
AFFECTED FEDRAMP PRODUCTS · 4
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |