S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-26855 Scanner

Detects 'Server-Side-Request-Forgery (SSRF)' vulnerability in Microsoft Exchange Server affects v. Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2019 Cumulative Update 8, Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 5, Microsoft Exchange Server 2019 Cumulative Update 6, Microsoft Exchange Server 2016 Cumulative Update 16, Microsoft Exchange Server 2019 Cumulative Update 7, Microsoft Exchange Server 2016 Cumulative Update 18.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-26855
9.1
CVSScritical
Exploitable remotely over the internet · no authentication required.
Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Microsoft Exchange Server 2013 Cumulative Update 21by Microsoft
AFFECTED< 15.00.1395.012SAFE ✓≥ 15.00.1395.012
Microsoft Exchange Server 2013 Cumulative Update 22by Microsoft
AFFECTED< 15.00.1473.006SAFE ✓≥ 15.00.1473.006
Microsoft Exchange Server 2013 Cumulative Update 23by Microsoft
AFFECTED< 15.00.1497.012SAFE ✓≥ 15.00.1497.012
Microsoft Exchange Server 2016 Cumulative Update 10by Microsoft
AFFECTED< 15.01.1531.012SAFE ✓≥ 15.01.1531.012
Updated Aug 19, 2026View on NVD →
Detail

Microsoft Exchange Server is a widely used email and calendaring system that businesses and organizations rely on for communication and collaboration. Introduced in 1996, the Exchange Server has since evolved into a comprehensive messaging platform, allowing users to manage contacts, tasks, and schedules all in one location. With the rise of remote work, the server has become even more critical in maintaining productivity and connectivity.

Among the several vulnerabilities that cybercriminals have been exploiting on Microsoft Exchange Servers, the CVE-2021-26855 is the most critical one. The vulnerability, which was discovered by Hafnium, a group linked to the Chinese government, is a server-side request forgery (SSRF) vulnerability. It occurs when a server can be tricked into making an unintended request to a remote server, which may give unauthorized access to its target.

When exploited, CVE-2021-26855 enables cybercriminals to remotely execute code on the Exchange Server. This flaw allows attackers to bypass authentication protocols, enabling them to gain access to sensitive data stored within the server. The attack chain starts with the exploitation of this vulnerability and can potentially lead to complete control of the Exchange Server, leak of sensitive data, and the installation of ransomware.

The Microsoft Exchange Server vulnerability disclosed by Hafnium has left many organizations vulnerable to attack. Luckily, there are proactive steps that system administrators can take to reduce the likelihood of a successful attack. Learning about vulnerabilities is critical in identifying potential risks and staying proactive in protecting assets. By utilizing s4e.io's advanced features, individuals can stay up-to-date on potential vulnerabilities and gain insights into ways to minimize risk. Stay safe, stay knowledgeable, and take action to secure your assets and data.

 

REFERENCES

Solution Advice

To protect against CVE-2021-26855, system administrators must take a few critical precautions, including:

  • Installing all mandatory security patches provided by Microsoft immediately.
  • Placing the Exchange Server inside a VPN to separate port 443 from external connection requests.
  • Considering adjusting the server configurations in an effort to disable OWA (Outlook Web Access) and ECP (Exchange Control Panel).
  • Monitoring the server for unusual login attempts and outgoing traffic.
  • Backing up the server regularly and storing those backups at a different location from the server.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.