← Threat Center
9.8
CRITICAL • CVSS 3.1

CVE-2021-26855

CISA KNOWN EXPLOITED

Microsoft Exchange Server Remote Code Execution Vulnerability

Prioritization

NVD CVSS
9.8
Published
Mar 2, 2021 7:15 PM EST
Modified
Aug 19, 2026 3:22 PM EDT
CISA KEV
Yes
KEV due date
2022-05-03
CISA required action

Apply updates per vendor instructions.

Red Hat context

No Red Hat-specific cached context is available for this record.

DEFENSIVE REMEDIATION WORKFLOW

Recommended response

  1. Treat as priority because it appears in CISA Known Exploited Vulnerabilities data; follow the required action and due date where applicable.
  2. Identify affected assets with Qualys, Tanium, software inventory, CMDB or configuration-management data.
  3. Confirm package/application applicability before change execution; CVSS alone does not prove that every host is vulnerable.
  4. Patch, upgrade, rehydrate or apply a vendor-approved mitigation through controlled change. GraceITS can automate eligible waves with Ansible/Tanium.
  5. Rescan after remediation and reconcile remaining exceptions, false positives, unsupported systems and compensating controls.