CVE-2026-21527
Microsoft Exchange Server 2016 … 2019
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NSummary
CVE-2026-21527 is a medium-severity Insufficient Verification of Data Authenticity (CWE-345) vulnerability in Microsoft Exchange Server. Its CVSS base score is 6.5 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 6% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SC-23 (Session Authenticity) and SI-10 (Information Input Validation) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-7340
Vulnerability Data
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
UI spoofing vuln in public-facing Exchange directly enables network-based spoofing for phishing/info gathering.
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
- 8 hardening rules · 5 OS baselines
V1.1.1V1.4.2V2.1.1V2.2.2
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces validation of syntactic and authenticity properties of inputs, addressing CWE-345/1286 root cause of spoofed UI data in Exchange.
Protects against spoofing by guaranteeing session authenticity and binding, directly countering network-based UI misrepresentation attacks.
Requires cryptographic integrity protection on transmissions, mitigating the network spoofing vector that enables CWE-451 UI misrepresentation.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly address design and implementation of accurate, non-spoofable UI elements.
CWE-345 directly impairs RC.RP-05's verification of restored-asset integrity/authenticity, largely defeating the outcome while still leaving other restoration-confirmation steps partially viable.
User awareness training helps people recognize and avoid harm from UI misrepresentation such as phishing, but does not prevent the flaw itself.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect missing or weak data authenticity verification.
Security awareness training can teach users to recognize UI misrepresentation and phishing attempts.
Network controls can enforce authenticated channels, reducing risk of accepting unauthentic data.
Secure network services often include authenticity checks for data exchanged over those services.
Web filtering can block known phishing sites that exploit UI misrepresentation.
Cryptographic mechanisms directly verify data origin and integrity, preventing acceptance of unauthentic data.