logo

Mapping MITRE ATT&CK to the Microsoft Exchange Zero-Day Exploits

ID: 82c2ffc9-351c-5546-adb6-d76b571d77a4

STIX ID: report--82c2ffc9-351c-5546-adb6-d76b571d77a4

Feed Name: ReliaQuest Blog

Threat Score
92/100

Date Published: 2021-03-11

Date Updated: 2026-04-29

...
...

This blog maps Microsoft’s March 2021 Exchange Server zero-day compromises to the MITRE ATT&CK framework, detailing four exploited CVEs (including CVE-2021-26855) used by HAFNIUM and multiple other actors to gain initial access, deploy web shells for persistence, and exfiltrate email data via C2. It highlights active exploitation at scale (Microsoft estimated ~30,000 compromised organizations), recommends immediate patching and investigation, and provides detection and mitigation guidance including Microsoft updates and scanning tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.