{"cveID":"CVE-2021-26857","vendorProject":"Microsoft","product":"Exchange Server","vulnerabilityName":"Microsoft Exchange Server Remote Code Execution Vulnerability","dateAdded":"2021-11-03","shortDescription":"Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-03","knownRansomwareCampaignUse":"Known","notes":"Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-26857","cwes":["CWE-502"],"year":2021,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2021-26857","technique":"T1133","technique_name_at_mapping":"External Remote Services","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"CVE-2021-26857, part of Proxy Logon, is an insecure deserialization vulnerability in the Unified Messaging service. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could execute arbitrary code as SYSTEM on the Exchange Server. Exploiting this vulnerability gave HAFNIUM the ability to run code as SYSTEM on the Exchange server. This requires administrator permission or another vulnerability to exploit.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-062a","https://www.microsoft.com/en-us/security/blog/2021/03/02/hafnium-targeting-exchange-servers/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-26857","technique":"T1505.003","technique_name_at_mapping":"Web Shell","mapping_type":"primary_impact","capability_group":"code_execution","comments":"CVE-2021-26857, part of Proxy Logon, is an insecure deserialization vulnerability in the Unified Messaging service. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could execute arbitrary code as SYSTEM on the Exchange Server. Exploiting this vulnerability gave HAFNIUM the ability to run code as SYSTEM on the Exchange server. This requires administrator permission or another vulnerability to exploit.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-062a","https://www.microsoft.com/en-us/security/blog/2021/03/02/hafnium-targeting-exchange-servers/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1133","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"External Remote Services","name_at_mapping":"External Remote Services","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":20,"has_detection_strategy":true},{"id":"T1505.003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Web Shell","name_at_mapping":"Web Shell","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":35,"has_detection_strategy":true}],"mapping_types":["primary_impact","secondary_impact"],"has_exploitation_technique":false,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":["cd479ccc-d8f0-4c66-ba7d-e06286f3f887"],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}