CVE-2021-26855: ProxyLogon
A server-side request forgery vulnerability in Microsoft Exchange Server that lets an unauthenticated attacker send arbitrary HTTP requests and have the Exchange server authenticate on their behalf. Chained with a post-authentication vulnerability (CVE-2021-27065), it gives an unauthenticated attacker full remote code execution and was used in mass exploitation of on-premises Exchange servers in early 2021.
View the authoritative record on NVD ↗Affected software
- Microsoft Exchange Server 2013
- Microsoft Exchange Server 2016
- Microsoft Exchange Server 2019
How it's exploited
Send a crafted HTTP request to the Exchange front end with a manipulated Cookie header that spoofs the server's own identity, tricking the SSRF into forwarding the request to the back end with server-level privileges, then chain to a webshell drop via CVE-2021-27065.
Severity
CVE-2021-26855 carries a CVSS 3.1 base score of 9.8, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2021-26855 is categorized under CWE-918, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Server-Side Request Forgery (SSRF) using Nuclei and OWASP ZAP, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 8 dedicated rules for this weakness.
Tools: Nuclei, OWASP ZAP
Remediation
Apply Microsoft's March 2021 Exchange Server security updates immediately, or the published interim mitigations if patching is delayed, and hunt for webshells left by prior exploitation before treating a server as clean.
Frequently asked questions
What is CVE-2021-26855?
A server-side request forgery vulnerability in Microsoft Exchange Server that lets an unauthenticated attacker send arbitrary HTTP requests and have the Exchange server authenticate on their behalf. Chained with a post-authentication vulnerability (CVE-2021-27065), it gives an unauthenticated attacker full remote code execution and was used in mass exploitation of on-premises Exchange servers in early 2021.
How severe is CVE-2021-26855?
CVE-2021-26855 has a CVSS 3.1 base score of 9.8 out of 10, rated Critical.
What software is affected by CVE-2021-26855?
CVE-2021-26855 affects Microsoft Exchange Server 2013; Microsoft Exchange Server 2016; Microsoft Exchange Server 2019.
How do you fix CVE-2021-26855?
Apply Microsoft's March 2021 Exchange Server security updates immediately, or the published interim mitigations if patching is delayed, and hunt for webshells left by prior exploitation before treating a server as clean.
Where is the authoritative record for CVE-2021-26855?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2021-26855 at https://nvd.nist.gov/vuln/detail/CVE-2021-26855, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest