CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-26857
Microsoft Exchange Server Remote Code Execution Vulnerability
Exploited in the wild (CISA KEV since Nov 3, 2021). microsoft reports CVSS 3.1 7.8. EPSS estimates 95.8% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
Microsoft Exchange Server Remote Code Execution Vulnerability
- State
- PUBLISHED
- Published
- Mar 2, 2021
- Updated
- Oct 21, 2025
- Evidence coverage
- 92%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: Microsoft Exchange Server Remote Code Execution Vulnerability
Inspect raw assertion
- Field
container- Value
- Microsoft Exchange Server Remote Code Execution Vulnerability
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft Exchange Server Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Exchange Server Remote Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 95.76% probability · 99.87th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.957620000000; percentile 0.998670000000
FIRST EPSS · score date Aug 26, 2026 · 99.9th percentile · first observed Aug 26, 2026
microsoft · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Microsoft Exchange Server Remote Code Execution Vulnerability
Inspect raw assertion
- Field
container- Value
- Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Exchange Server Remote Code Execution Vulnerability
95.76% probability · 99.87th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.957620000000; percentile 0.998670000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
27 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "14.0.0.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.00.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.00.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.00.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.00.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.01.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.01.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.01.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.01.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.01.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.01.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.01.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.01.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.01.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.01.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.01.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.01.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.02.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.02.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.02.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.02.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.02.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.02.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.02.0", "lessThan": "publication", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.02.0", "lessThan": "publication", "versionType": "custom"}]Affected-product evidence
Accepted scope and product mapping
1 canonical links · 1 source-reported links
vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-d87daca995d075bf30565cc429e7242a47683272975068df1d327ec1d8ff609c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 25
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1f026ea1-8143-4ac8-bcc0-e7f15f8f34832575c180-31d1-4a94-b13c-328d245310442f1a04b7-ba40-48ca-90b3-02b48396014c3c529726-8306-44dc-9d25-c2606f31d46b49cda388-1285-43e4-b445-3b65b188531c4bce6a5c-bf78-4947-9358-b45bb0615b875a56b9af-e186-470f-bd1e-2827cde763645aa7da02-bd17-4054-b4f7-3265e70d864c61773505-6b42-4ba5-bd7e-dc0958f6c896694f2e9c-27b4-4e58-a275-de2573e8444a6b857e12-45bc-4b39-a8f9-a5678dd3422770cc648f-a1d5-4e1a-b94e-dd1b7cd41fbd80e2685f-7589-496b-887f-b95dd4e7a67e825264b0-76c9-4cc1-8ee9-c853d3c10a9492bf8f0a-71c0-4ae4-9285-8287c5bad8659ca6bd97-6aba-42d1-a74d-b56555a73e90a2dc70c6-f45d-49fc-bd4b-5820f8db4621b3616555-e245-4e50-8396-6443ba75a418b83a61e4-07ad-4725-87a5-f6fc189a2b11c1cbf8c2-01ea-4e1e-9ffb-7ff858c9d0bfc9f79b52-ce81-496a-98e7-ead42b851f43de32ae0a-a80d-4c2d-b6ce-6ef1af157206dffb42c6-a93f-494f-b44c-1e3a719d2173fb18fe00-66d5-4553-8828-0535d6063adafc7abd97-4aab-405a-a623-df9db7553923Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 26
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
04ea1a88-716c-4ed7-bf83-8a03f9dd32ed0cb5b9d7-f794-4df6-bb10-39fd8acf4b7d25a5f01c-9cde-4d32-ac30-4394a90b1f7727645160-cabb-4417-ba19-62914349b9bd31fa6f02-f771-4ee0-8341-6427abceee4f3638f0d3-a5f9-42cc-aac7-c2aff135096841435072-52fe-4819-be28-5639156bef7f42f23898-ae0d-4e1f-a2e0-39f6047d9a09538a4ef3-c4d4-4fd1-9baa-b1717c89e5af60d000ee-f450-4a98-8acc-7a75407aa02e65003686-0ab3-4c9c-8cc4-15b8610793d08c306da1-1c91-4d57-a7c7-b1c08390a557905bff82-ad43-47bf-b243-bccace234cdc90e6f711-79d0-4a15-9d03-ebd7994652b999ced557-86f0-4ea5-a89d-1bc1b6888adfa0b8ac76-a5ed-4378-9fb7-45d0614cbeeca0f0c11e-e2aa-478f-b401-609fdee2b857a9041998-642d-428f-81aa-1ac6b25897fbc4e21f63-cf84-47a8-b3b1-2807d66492a2cff209ee-0b3e-466a-9cd1-4e3ec68be5e3d5ed104a-38f5-4f65-b51a-ef6a071c0434dc7760d1-6193-4f76-9dd5-7815ba4841abdd2a7304-c6ed-4d57-87a6-0f01b9646487e222bbff-d440-48cd-9128-ae0e73480553e5f2433a-a7d7-44f3-9e53-7076f5ac6853fe978e1c-9d05-459a-a6cc-735097d85784Assessments
CVSS by origin
AV:N/AC:M/Au:N/C:P/I:P/A:PCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:CDirect CVE/CNA normalized decisions
microsoft
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C- Validation
- Valid match
- Recomputed
- 7.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.