NVD disclosure day

Published threat advisories for March 3, 2021

CVE advisoryKnown Exploit

CVE-2021-27065

Microsoft Exchange Server Remote Code Execution Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Microsoft Exchange Server allows for remote code execution, potentially impacting data confidentiality, integrity, and availability. This poses a business risk due to the possibility of attackers gaining control of affected systems and causing service disruptions. Organizations should address this is

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-26858

Microsoft Exchange Server Remote Code Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Microsoft Exchange Server is affected by a remote code execution vulnerability. This could allow attackers to write arbitrary files to servers, potentially leading to system compromise and data exfiltration. This presents a business risk of unauthorized access and control over affected systems.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-26857

Microsoft Exchange Server Remote Code Execution Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Microsoft Exchange Server has a vulnerability that permits unauthorized code execution. This could lead to system compromise and data loss for affected organizations. The business risk is significant, requiring prompt attention to mitigate potential impacts on operations and data security.

• CISA KEV