Skip to content
COOEY

EXPOSURES › CVE-2021-27085

CVE-2021-27085

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-27085 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

Microsoft Internet Explorer had a remote code execution vulnerability that was actively exploited in the wild.

Internet Explorer contained an unspecified vulnerability allowing remote code execution, which was listed in CISA's KEV catalog as actively exploited. DIB organizations must care because unpatched legacy browsers can serve as an entry point for attackers to execute arbitrary code on systems, violating CMMC/NIST 800-171 requirements for patch management and system hardening. Organizations should immediately disable or patch IE and ensure all legacy software is updated or removed to prevent exploitation.

Shame score — A known remote code execution vulnerability in a widely used product was actively exploited in the wild, indicating negligent patching and avoidable exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Widespread acknowledgement of a significant security issue, coupled with a focus on the sheer volume of vulnerabilities needing remediation, suggests a negative perception of Microsoft's security post
cyberpress.org ↗ severe-fallout -0.80
Highlights exploitation of zero-days and large number of vulnerabilities
"Microsoft’s July 2026 Patch Tuesday delivered its largest security update ever, resolving 570 vulnerabilities..."
cooey ↗ severe-fallout -0.50
Neutral reporting of the vulnerability
"Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution."
www.pcworld.com ↗ severe-fallout -0.40
Highlights large number of flaws
"Microsoft's July patches fix over 600 flaws, shattering last month's record"
www.windowslatest.com ↗ severe-fallout -0.30
Acknowledges patching but highlights scale of problem
"Microsoft just patched a record 570 flaws, 4x last year as AI accelerates attacks"
app.opencve.io ↗ severe-fallout -0.20
Lists Microsoft among vendors with vulnerabilities
"6 Apple , Linux , Microsoft and 3 more"
www.cvefind.com ↗ severe-fallout -0.10
Lists Microsoft among vendors with CVEs
"Microsoft CVEs and Security Vulnerabilities"
NVD ↗ severe-fallout +0.00
Standard NVD reporting
"NVD - CVE-2026-57085"
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized