CVE-2021-26857
KEV ransomwaremass1Deserialization RCE in Microsoft Exchange Server Unified Messaging (ProxyLogon)
CISA: Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26857 is an insecure deserialization (CWE-502) remote code execution flaw in the Unified Messaging service of Microsoft Exchange Server. Although Microsoft scored it as a local attack vector (CVSS 3.1 7.8), it was exploited in the wild as part of the four-zero-day 'ProxyLogon' chain alongside the CVE-2021-26855 server-side request forgery flaw, turning unauthenticated HTTP requests into arbitrary code execution. Successful exploitation gives an attacker code execution on the mail server, from which they can read mailboxes, plant webshells, and move laterally; CISA notes known ransomware use in addition to espionage activity. Only on-premises Exchange deployments are affected — Exchange Server 2013, 2016, and 2019 prior to Microsoft's March 2021 fixes — while Microsoft's hosted Exchange Online service was not. Exploitation is confirmed and ongoing: EPSS rates it at 95.8% exploitation probability, it has been in CISA's Known Exploited Vulnerabilities catalog since November 2021, and headlines show multiple China-linked APT groups (e.g., HAFNIUM-linked campaigns, Calypso APT, Silk Typhoon) continuing to target vulnerable Exchange servers.
What to do: Apply Microsoft's March 2021 security updates (KB5000871) or any later cumulative update for on-premises Exchange Server 2013, 2016, or 2019; as a stopgap, restrict or disable the Unified Messaging service if it is not used. Hunt for compromise by checking Unified Messaging application event logs for 'System.InvalidCastException' entries, HttpProxy/Autodiscover logs for anomalous requests, and signs of post-exploitation such as webshells or unexpected processes spawned by w3wp.exe or UMWorkerProcess. Because the flaw is in CISA's KEV catalog with known ransomware use, treat patching as a priority action and verify no residual webshells or attacker persistence after updating.
| microsoft Exchange Server (on-premises) | Exchange Server 2013, 2016, and 2019 before the March 2021 security updates (KB5000871) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Exchange Server Remote Code Execution Vulnerability
- Affected
- Microsoft Exchange Server
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- exchange server
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H