Warning: 4 zero-day flaws in Exchange Server

Warning level: Critical

Microsoft has just issued emergency patches for 4 vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) in Exchange Server. Exploiting these flaws, hackers can hijack the server, install malware and steal data. These are critical with CVSS of 9.1/10.

Currently, hacker groups around the world are scanning and attacking. As recorded by Bkav, in Vietnam, many state agencies, banking and financial institutions are still using the vulnerable versions of Microsoft Exchange. Due to the important nature of the mail server, the risk of exploitation is high.

We suggest agencies and organizations urgently review and update the patches for their systems, quickly check and update the patches according to Microsoft's guidance here.


