CVE-2013-5936Active Exploitation(open-xchange / open-xchange_appsuite)

LOWCVSS 4.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for open-xchange open-xchange_appsuite systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 allows remote attackers to obtain sensitive information about (1) runtime activity, (2) network configuration, (3) user sessions, (4) the memcache interface, and (5) the REST interface via API calls such as a hazelcast/rest/cluster/ call, a different vulnerability than CVE-2013-5200.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open-xchange_appsuite

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • 2 total mentions across 1 day

Affected systems

Products
open-xchange_appsuite

4 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-01-28: 2Active Exploitation · 2026-01-28: 201-28
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2013-5936 — UCLOUD INFORMATION TECHNOLOGY HK LIMITED Visit -- https://cti.loginsoft.com/ip/118.194.236.137 #Loginsoft #Cytellite #Cybersecurity #CVE20135936 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/q798uw0RoT

    Post summary

    The tweet reports that CVE-2013-5936 is currently being targeted, implying active exploitation, but provides no further technical or remedial information.

    0000042
    19 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2013-5936 — UCLOUD INFORMATION TECHNOLOGY HK LIMITED Visit -- https://cti.loginsoft.com/ip/118.194.236.137 #Loginsoft #Cytellite #Cybersecurity #CVE20135936 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/fMNxEYTe8Q

    Post summary

    The tweet reports that Cytellite detected activity against CVE‑2013‑5936, indicating active exploitation, but offers no PoC, exploit code, or mitigation details.

    0000036
    19 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appopen-xchangeopen-xchange_appsuite7.0.1--
Appopen-xchangeopen-xchange_appsuite7.0.2--
Appopen-xchangeopen-xchange_appsuite7.2.0--
Appopen-xchangeopen-xchange_appsuite7.2.1--

Explore more