CVE-2020-0688Active Exploitation(microsoft / exchange_server)

HIGHCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft exchange_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

7.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-287

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_server

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 4d ago at 1 mentions (2026-03-20); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
exchange_server

4 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-20: 1Mentions · 2026-05-15: 1Mentions · 2026-07-28: 1Mentions · 2026-09-16: 1Mentions · 2026-09-17: 1PoC Mentioned / Linked · 2026-09-17: 1Exploit Tool / Code · 2026-09-16: 1Active Exploitation · 2026-07-28: 1Active Exploitation · 2026-09-16: 1Active Exploitation · 2026-09-17: 1Technical Details · 2026-09-16: 1Technical Details · 2026-09-17: 103-2005-1507-2809-1609-17
Signal classification2 categories
Active Exploitation
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-201
General1
2026-05-151
General1
2026-07-281
Active Exploitation1
2026-09-161
Active Exploitation1
2026-09-171
Active Exploitation1
Full discourse5 posts
  • CTI Traffic@CTITraffic
    Active Exploitation

    intrusiontruth: A recovered PLA 8th Technical Reconnaissance Bureau (Unit 61046) eDiary exposes APT15 espionage against governments across Africa and the Middle East, the African Union, and the Royal Thai Armed Forces. Access via Exchange CVE-2020-0688. https://intrusiontruth.wordpress.com/2026/07/28/turns-out-the-ghost-was-the-pla/

    Post summary

    The post claims that the PLA 8th Technical Reconnaissance Bureau accessed target systems via Microsoft Exchange CVE‑2020‑0688, demonstrating real‑world exploitation of the vulnerability.

    0401371.3K
    217 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    NightEagle APT exploited Exchange servers using CVE-2020-0688, then established covert C2 through Microsoft dev tunnels and GitHub repositories. The group conducted DCSync attacks to compromise Active Directory infrastructure after moving laterally via RDP tunneling. Runtime segmentation could have limited their internal pivoting across network segments. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/nighteagle-apt-ghostcontainer-tunneling-2024

    Post summary

    The text reports that the NightEagle APT actively exploited CVE-2020-0688 in Exchange servers as part of a broader campaign involving C2 communication, DCSync attacks, and lateral movement. Although no specific exploit tool is named, the focus is on real-world usage of the CVE, supported by a link to detailed threat research.

    10120117
    2.0K followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The content consists solely of a list of Windows CVE identifiers without any additional detail.

    10000106
    15 followersView on X
  • David@davidsheyi
    General

    8/ Regularly update firewall and router configurations. Misconfigurations can open doors for attackers, as seen in CVE-2020-0688 exploits. #CyberSecurity #NetworkSecurity

    Post summary

    The tweet recommends regular configuration updates and alludes to CVE-2020-0688 as an example of exploitation risk, but provides no technical details or evidence of active exploitation.

    1000030
    555 followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    NightEagle operators hit Exchange via CVE-2020-0688 to plant GhostContainer. They pull the http://ASP.NET machine keys, then overwrite VIEWSTATE so the server deserializes attacker-controlled data and executes payloads straight from memory. GhostWebShell plus Neo-reGeorg handle persistence while Microsoft dev tunnels and rdp2tcp move traffic laterally; CVE-2019-0708 and DCSync round out the chain. Hacking Cat started in Feb 2024 abusing CVE-2021-26855 to drop the Go-based Gorilla RAT. From there they push Monkey ransomware builds in Rust, .NET, C++, or Go. The Rust samples use ChaCha20-Poly1305; the .NET ones stick to AES-256-CBC. Artifacts first appeared late summer 2025. Toy Ghouls has run mqtt-bird-agent and matrix-bird-agent since mid-2026. Both register as Windows services, seed their keys from MachineGuid, and beacon over HiveMQ MQTT or Element Matrix after Evil-WinRM entry. Track the distinct TTP sets on the same Exchange hosts before you merge the incidents.

    Post summary

    The text details active, ongoing exploitation campaigns by three named threat actors (NightEagle, Hacking Cat, Toy Ghouls) targeting Exchange servers via CVE-2020-0688, CVE-2019-0708, and CVE-2021-26855, with specific named malware, technical attack chains, and persistence mechanisms.

    00000100
    172 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_server2010--
Appmicrosoftexchange_server2013--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--

Explore more