CVE-2021-26858
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
In plain language
AI Act nowCVE-2021-26858 is a Microsoft Exchange Server weakness that can let attackers run malicious code; if your business runs affected Exchange Server updates, you should treat this as an urgent patching priority.
CVE-2021-26858 is a Microsoft Exchange Server Remote Code Execution vulnerability that has been confirmed in real-world ransomware activity (CISA KEV) and is addressed by specific Exchange Cumulative Update fixes.
What to do now
- Check whether you run Microsoft Exchange Server and which Exchange version/Cumulative Update you have installed.
- Compare your installed Exchange Cumulative Update against the fixed versions below and treat any matching “earlier than fixed” update as affected.
- Update Microsoft Exchange Server to the fixed version for your current Cumulative Update track:
- Exchange 2013 CU21 → 15.00.1395.012
- Exchange 2013 CU22 → 15.00.1473.006
- Exchange 2013 CU23 → 15.00.1497.012
- Exchange 2016 CU10 → 15.01.1531.012
- Exchange 2016 CU11 → 15.01.1591.018
- Exchange 2016 CU12 → 15.01.1713.010
- Exchange 2016 CU13 → 15.01.1779.008
- Exchange 2016 CU14 → 15.01.1847.012
- Exchange 2016 CU15 → 15.01.1913.012
- Exchange 2016 CU16 → 15.01.1979.008
- Exchange 2016 CU17 → 15.01.2044.013
- Exchange 2016 CU18 → 15.01.2106.013
- Verify after updating that the Exchange binaries are at the fixed build and follow Microsoft’s update guidance for any required restart/reconfiguration steps.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-26858 and every CVE in our database. Create a free account — no credit card required.
Create Free Account