CVE Tools

CVE-2021-26858

Exploited in the wild. In CISA KEV since 2021‑11‑03. A vendor fix is available.

Published Updated Sources: CVE.org, NVD, BDU

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check whether you run Microsoft Exchange Server and which Exchange version/Cumulative Update you have installed.
  2. Compare your installed Exchange Cumulative Update against the fixed versions below and treat any matching “earlier than fixed” update as affected.
  3. Update Microsoft Exchange Server to the fixed version for your current Cumulative Update track:
    • Exchange 2013 CU21 → 15.00.1395.012
    • Exchange 2013 CU22 → 15.00.1473.006
    • Exchange 2013 CU23 → 15.00.1497.012
    • Exchange 2016 CU10 → 15.01.1531.012
    • Exchange 2016 CU11 → 15.01.1591.018
    • Exchange 2016 CU12 → 15.01.1713.010
    • Exchange 2016 CU13 → 15.01.1779.008
    • Exchange 2016 CU14 → 15.01.1847.012
    • Exchange 2016 CU15 → 15.01.1913.012
    • Exchange 2016 CU16 → 15.01.1979.008
    • Exchange 2016 CU17 → 15.01.2044.013
    • Exchange 2016 CU18 → 15.01.2106.013
  4. Verify after updating that the Exchange binaries are at the fixed build and follow Microsoft’s update guidance for any required restart/reconfiguration steps.

What it is

From the CVE record

Microsoft Exchange Server Remote Code Execution Vulnerability

In plain language

Written by AI from the record

CVE-2021-26858 is a Microsoft Exchange Server weakness that can let attackers run malicious code; if your business runs affected Exchange Server updates, you should treat this as an urgent patching priority.

CVE-2021-26858 is a Microsoft Exchange Server Remote Code Execution vulnerability that has been confirmed in real-world ransomware activity (CISA KEV) and is addressed by specific Exchange Cumulative Update fixes.

If you're affected

  • Full server takeover
  • Email account compromise
  • Ransomware risk
  • Service disruption

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS99th
CISA KEV
CISA KEV

Listed as exploited in the wild since 2021-11-03.

US federal agencies must remediate by 2022-05-03.

Known use in ransomware campaigns.

Apply updates per vendor instructions.
Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

94% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

14 events over 1997 days, from the signal feeds we watch.

  1. EPSS band changehigh → criticalepss band change
  2. Patch availablerecord updated
  3. Patch availablerecord updated
  4. OpenVAS check added
  5. EPSS band changemoderate → high
  6. EPSS band changehigh → moderate

Affected products

Technical detail

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Scored 7.8 by NVD.

How it is reached

  • Attack Vector LocalRequires local access to the vulnerable system (e.g. local login, malicious file)
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction RequiredA user must click a link, open a file, or perform some action

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Microsoft Corp, not every advisory. This one: actively exploited.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store