LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-26857: Microsoft Exchange Server Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-26857 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

CVE-2021-26857 is a remote code execution vulnerability in Microsoft Exchange Server. It is part of the ProxyLogon exploit chain and has been used by ransomware operators, so unpatched servers face a realistic risk of full compromise.

IT and security teams should treat this as a high-priority item: confirm whether Exchange is in your environment, apply the vendor updates, and watch for signs of prior abuse. Specifics such as exact builds and patch identifiers must be confirmed against the Microsoft advisory.

How it works

The weakness is classified as CWE-502 (Deserialization of Untrusted Data). In products that accept serialized objects from the network or from other components, an attacker who can supply crafted input may cause the application to reconstruct objects in an unsafe way. When that reconstruction triggers attacker-controlled code paths, the result can be remote code execution in the context of the Exchange process.

Public detail on the precise trigger for CVE-2021-26857 is limited beyond the fact that it enables remote code execution and sits in the ProxyLogon chain. Defenders should assume that a remote attacker who can reach the vulnerable Exchange endpoint can achieve code execution if the server is unpatched. Do not rely on unconfirmed exploit write-ups; validate behavior and indicators against the vendor advisory and your own telemetry.

Am I affected? How to find it in your systems

Microsoft Exchange Server typically runs on Windows servers inside the organization or in hosted environments that you manage. Inventory every host that provides mailbox, Client Access, or related Exchange roles.

When version or configuration details are unclear, treat the server as potentially affected until you have verified it against the vendor advisory.

How to remediate

Patching is the primary fix. Apply the Microsoft updates that address CVE-2021-26857 on every affected Exchange Server, following the vendor’s installation order and prerequisites. CISA’s required action is to apply updates per vendor instructions; schedule this as an emergency change if the servers are reachable from untrusted networks.

If you can't patch immediately

If you must delay the update, reduce exposure until the patch can be installed.

These steps lower risk but do not eliminate it; schedule the official update as soon as practicable.

If your data may have been exposed

Actively exploited vulnerabilities, including those used by ransomware, frequently lead to data theft or follow-on intrusion. If logs or EDR indicate exploitation, or if the server was internet-facing and unpatched during the relevant window, initiate your incident-response process: isolate affected hosts, preserve evidence, reset privileged credentials, and assess mail and file data for exfiltration.

You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts have appeared in prior dumps, then enforce password changes and MFA where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Exchange Server
WeaknessCWE-502
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities