Known exploited / historically exploited security risk
CVE-2021-34473 — Microsoft Exchange Server
A Microsoft Exchange Server remote code execution vulnerability associated with active exploitation campaigns and included in CISA's Known Exploited Vulnerabilities program.
Business relevance
If Microsoft Exchange Server is present in your environment, confirm whether the installed version and configuration are affected. The existence of this CVE does not by itself prove that a specific system is vulnerable or compromised.
What to check
- Identify on-premises Microsoft Exchange servers.
- Record Exchange version and cumulative update level.
- Confirm applicable Microsoft security updates are installed.
- Review internet exposure and compromise indicators where applicable.
Source record
Authoritative source: CISA advisories on exploited Microsoft Exchange vulnerabilities and Known Exploited Vulnerabilities program.
CompFlorida record reviewed: September 21, 2026.
Vendor: Microsoft
Product: Microsoft Exchange Server
CVE: CVE-2021-34473
Need help checking applicability?
CompFlorida can help identify the product/version in use, review exposure and coordinate the appropriate remediation path.
Request a Technology Risk Review
