CVE-2023-21529Active Exploitation(microsoft / exchange_server)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch microsoft exchange_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Exchange Server Remote Code Execution Vulnerability

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_server

Threat summary

  • Active exploitation appears in 8 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 6 observed days

What's happening

  • Active exploitation reported across 8 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 10 signals
  • General: 2 classified signals
  • Peaked 4d ago at 6 mentions (2026-04-14); latest day: 1
  • 14 total mentions across 6 days

Affected systems

Vendors
Products
exchange_server

3 versions affected across 1 product

Deep dive

Activity timeline14 mentions / 6d
02356Mentions · 2026-04-13: 2Mentions · 2026-04-14: 6Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1Mentions · 2026-04-27: 3Mentions · 2026-04-29: 1PoC Mentioned / Linked · 2026-04-14: 1Active Exploitation · 2026-04-13: 2Active Exploitation · 2026-04-14: 3Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-04-27: 1Active Exploitation · 2026-04-29: 1Patch / Workaround · 2026-04-14: 2Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 6Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-29: 104-1304-1404-1504-1604-2704-29
Signal classification4 categories
Active Exploitation
857.1%
Patch
321.4%
General
214.3%
Disclosure
17.1%
Referenced assets22 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-132
Active Exploitation2
2026-04-146
Active Exploitation3Disclosure1General1Patch1
2026-04-151
Active Exploitation1
2026-04-161
General1
2026-04-273
Active Exploitation1Patch2
2026-04-291
Active Exploitation1
Full discourse14 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    6 ثغرات تهدد اغلب الاجهزة والشبكات يتم استغلالها حاليا 🚨 CISA أضافت 6 ثغرات جديدة لقائمة (KEV)Known Exploited Vulnerabilities بعد تأكد الاستغلال الفعلي لها حاليا من قبل المخترقين. الثغرة CVE-2026-21643 (CVSS: 9.1) 🔴 المنتج: FortiClient EMS من Fortinet النوع: SQL Injection التأثير: تنفيذ كود خبيث بدون مصادقة الحالة: استغلال مؤكد منذ 24 مارس 2026 الثغرة CVE-2020-9715 (CVSS: 7.8)🟠 المنتج: Adobe Acrobat Reader النوع: Use-After-Free التأثير: Remote Code Execution ثغرة تستغل من (2020) ولكن تم اكتشافها والاعلان عنها مؤخرا الثغرة CVE-2023-36424 (CVSS: 7.8) 🟠 المنتج: Microsoft Windows Common Log File System Driver النوع: Out-of-Bounds Read التأثير: Privilege Escalation ما فيه تقارير استغلال علنية، بس CISA تؤكد انها تتسغل حاليا . الثغرة CVE-2023-21529 (CVSS: 8.8) 🔴 المنتج: Microsoft Exchange Server النوع: Deserialization of Untrusted Data التأثير: Remote Code Execution المجموعة الصينية Storm-1175 تستغلها لـ Medusa Ransomware. الثغرة CVE-2025-60710 (CVSS: 7.8)🟠 المنتج: Host Process for Windows Tasks النوع: Improper Link Resolution Before File Access التأثير: Local Privilege Escalation الثغرة CVE-2012-1854 (CVSS: 7.8) 📅🟠 المنتج: Microsoft Visual Basic for Applications (VBA) النوع: Insecure Library Loading التأثير: Remote Code Execution ثغرة من 2012! Microsoft عمرها ١٤ سنه ولاتزال تستغل

    Post summary

    The post enumerates six highly‑severed vulnerabilities confirmed in active exploitation, providing detailed technical attributes but no PoC, exploit code, or remediation information.

    16020152.6K
    49.2K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/13追加) 🛡️No.1561 CVE-2012-1854 Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability ✅概要 ・深刻度:重要 7.8 (CVSS Base) / CISA-ADP ・種別:信頼できない検索パス (CWE-426) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft Visual Basic for Applications (VBA) において、DLL検索パスの処理に不備が存在。事前認証されていない攻撃者により、細工されたDLLを特定ディレクトリに配置されることで、正規ライブラリにかわって読み込まされる恐れがある。結果、ユーザーが対象ファイルを開くことで、任意コードが実行される可能性がある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・攻撃者がDLLを配置できる環境であること ・ユーザーが細工されたファイルを開くこと ・VBAが有効な環境 ________________________________________ ✅悪用時影響 ・任意コード実行(ユーザー権限) ・情報漏えいおよび改ざん ・システム可用性への影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2012-1854 https://learn.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-046   🛡️No.1562 CVE-2025-60710 Microsoft Windows Link Following Vulnerability ✅概要 ・深刻度:重要 7.8 (CVSS Base) / Microsoft Corporation ・種別:リンク解釈の問題 (CWE-59) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Windows において、リンク解決処理に不備が存在。認証済みの攻撃者により、細工されたリンクを介して、本来アクセスできないリソースへアクセスされ、ローカル環境で権限昇格される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・ローカルアクセスが可能であること ・低権限ユーザーであること ・ユーザー操作不要 ________________________________________ ✅悪用時影響 ・権限昇格 ・機密情報の取得および改ざん ・システムへの影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-60710 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710   🛡️No.1563 CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability ✅概要 ・深刻度:8.8 High (CVSS Base) / NVD ・種別:信頼できないデータのデシリアライゼーション (CWE-502) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Exchange Serverにおいて、信頼できないデータのデシリアライズ処理に起因する脆弱性が存在。認証済みの攻撃者により、細工されたデータをサーバー上で処理されることで、コード実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・認証済みユーザ権限が必要 ・Exchange Serverへのネットワークアクセス ________________________________________ ✅悪用時影響 ・任意コード実行 ・情報漏えい、改ざん、サービス影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-21529 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21529   🛡️No.1564 CVE-2023-36424 Microsoft Windows Out-of-Bounds Read Vulnerability ✅概要 ・深刻度:7.8 High (CVSS Base) / NVD ・種別:境界外読み取り (CWE-125) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Microsoft Windowsにおいて、境界外読み取りに起因する脆弱性が存在。認証済みの攻撃者により、不正なメモリアクセスを引き起こされることで、機密情報を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:高 ________________________________________ ✅攻撃前提条件 ・ローカルでのログオン権限が必要 ________________________________________ ✅悪用時影響 ・機密情報の漏えい ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-36424 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36424   🛡️No.1565 CVE-2020-9715 Adobe Acrobat Use-After-Free Vulnerability ✅概要 ・深刻度:7.8 High (CVSS Base) / NVD ・種別:解放後使用 (CWE-416) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Adobe AcrobatおよびReaderにおいて、解放後使用に起因する脆弱性が存在。事前認証されていない攻撃者により、細工されたPDFファイルをユーザーに開かせることで、メモリ破損を引き起こし、任意のコードを実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・ユーザが細工されたPDFファイルを開く必要がある ________________________________________ ✅悪用時影響 ・任意コード実行 ・情報の取得、改ざん、システム影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2020-9715 https://helpx.adobe.com/security/products/acrobat/apsb20-48.html   🛡️No.1566 CVE-2026-21643 Fortinet FortiClientEMS SQL Injection Vulnerability ✅概要 ・深刻度:9.8 Critical (CVSS Base) / NVD ・種別:SQLインジェクション (CWE-89) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Fortinet FortiClientEMSにおいて、SQLコマンドで使用される特殊要素の不適切な無効化に起因する脆弱性が存在。事前認証されていない攻撃者により、細工されたHTTPリクエストを送信されることで、SQLインジェクションを引き起こされる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・対象システムへネットワークアクセス可能 ________________________________________ ✅悪用時影響 ・任意コマンド実行 ・機密情報の漏えい、改ざん、サービス停止 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:あり(セキュリティ企業による報告) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-21643 https://www.fortiguard.com/psirt/FG-IR-26-XXX   🛡️No.1567 CVE-2026-34621 Adobe Acrobat and Reader Prototype Pollution Vulnerability ✅概要 ・深刻度:8.6 High (CVSS Base) / Adobe Systems Incorporated ・種別:オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染) (CWE-1321) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Adobe AcrobatおよびReaderにおいて、オブジェクトプロトタイプ属性の不適切に制御された変更に起因する脆弱性が存在。ユーザー権限で任意のコードを実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・被害者が悪意のあるファイルを開く必要がある ・対象端末でAdobe AcrobatまたはReaderが利用されている必要がある ________________________________________ ✅悪用時影響 ・現在のユーザー権限で任意コード実行 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:Adobeが悪用を確認 (Adobeヘルプセンター) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-34621 https://helpx.adobe.com/security/products/acrobat/apsb26-43.html https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post announces seven CVEs added to the CISA KEV catalog, providing technical details, patch references, and notes that at least one vulnerability has confirmed exploitation; however, no exploit code is disclosed.

    000635.7K
    43.5K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    CISA added 7 CVEs to the KEV catalog today. All confirmed active exploitation. CVE-2012-1854 — Microsoft VBA insecure library loading CVE-2020-9715 — Adobe Acrobat UAF CVE-2023-21529 — Exchange deserialization CVE-2023-36424 — Windows OOB read CVE-2025-60710 — Windows link following CVE-2026-21643 — Fortinet SQL injection CVE-2026-34621 — Adobe Acrobat prototype pollution A CVE from 2012 is still being actively exploited in 2026. Patch prioritization isn’t optional. Source: https://t.me/VulnerabilityNews/41878 → http://cisa.gov/known-exploited-vulnerabilities-catalog

    Post summary

    CISA has added seven CVEs to the KEV catalog and confirmed they are actively exploited, covering vulnerabilities in Microsoft, Adobe, Exchange, and Fortinet, underscoring ongoing exploitation risks.

    11030214
    184 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性7件をカタログに追加 CISA Adds Seven Known Exploited Vulnerabilities to Catalog #CISA (Apr 13) CVE-2012-1854 Microsoft Visual Basic for Applications のライブラリ読み込みの脆弱性 CVE-2020-9715 Adobe AcrobatのUse-After-Free脆弱性 CVE-2023-21529 Microsoft Exchange Serverにおける信頼できないデータの逆シリアル化の脆弱性 CVE-2023-36424 Microsoft Windows 境界外読み取りの脆弱性 CVE-2025-60710 Microsoft Windows リンク追跡の脆弱性 CVE-2026-21643 FortinetのSQLインジェクション脆弱性 CVE-2026-34621 Adobe AcrobatおよびReaderプロトタイプ汚染の脆弱性 https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog

    Post summary

    The alert lists seven CVEs confirmed to be actively exploited in the wild, providing concise technical details but no proof‑of‑concept or patch information.

    00030341
    4.9K followersView on X
  • Inferlume@inferlume_hq
    Patch

    Actions for today: patch Exchange CVE-2023-21529, update Chrome, patch Fortinet CVE-2026-21643, review Cisco FMC, replace D-Link DIR-823X, update Breeze Cache, and block unverified Teams external contact requests.

    Post summary

    The post lists immediate security actions, specifically patching two CVEs (Exchange CVE-2023-21529 and Fortinet CVE-2026-21643), updating software, and blocking unverified Teams requests.

    10000110
    1 followersView on X
  • Inferlume@inferlume_hq
    Patch

    Healthcare, education, finance, and professional services organizations in Australia, the UK, and the US are confirmed Storm 1175 targets. The CISA federal patch deadline for CVE-2023-21529 expired today.

    Post summary

    CISA has announced that the federal patch deadline for CVE‑2023‑21529 has expired today, highlighting that multiple sectors in Australia, the UK, and the US are targets of the Storm 1175 threat group.

    1000065
    1 followersView on X
  • Inferlume@inferlume_hq
    Active Exploitation

    Storm 1175, a China based financially motivated actor, is deploying Medusa ransomware via Exchange CVE-2023-21529. Microsoft confirms this group goes from initial access to encrypted files in under 24 hours.

    Post summary

    Storm 1175 is actively exploiting Microsoft Exchange CVE‑2023‑21529 to deploy Medusa ransomware, achieving file encryption within 24 hours.

    1000077
    1 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    General

    CVE-2023-21529 Microsoft Exchange Serverにおける信頼できないデータの逆シリアル化の脆弱性 CVE-2023-36424 Microsoft Windows 境界外読み取りの脆弱性 CVE-2025-60710 Microsoft Windows リンク追跡の脆弱性 CVE-2026-21643 FortinetのSQLインジェクション脆弱性

    Post summary

    The passage merely lists several Microsoft and Fortinet CVEs along with brief Japanese descriptions, providing some technical details but no evidence of exploitation, PoC, patch information, or false‑positive claims.

    10000378
    40 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Active Exploitation

    🔴 Ransomware Intel WANNACRY Ransomware Gang: 33 New Victims Posted — Critical Infrastructure Targe… "CVE-2023-21529:** Microsoft Exchange Server Deserialization CVE-2026-20131:**…" 🔗 https://securityarsenal.com/blog/wannacry-ransomware-gang-33-new-victims-posted-critical-infrastructure-targeting-and-detection-rules #CyberSecurity #ThreatIntel #ransomwaregang #wannacry #ransomware

    Post summary

    The tweet announces 33 new Wannacry ransomware victims, highlighting CVE‑2023‑21529 (Exchange deserialization) and CVE‑2026‑20131, and indicates the vulnerability is being actively exploited, though it offers no PoC or patch details.

    0000091
    14 followersView on X
  • XHack@xhackio
    General

    🛡️ Microsoft Exchange Deserialization RCE Explained CVE-2023-21529 is a critical vulnerability in Microsoft Exchange Server. It involves the deserialization of untrusted data, allowing an authenticated attacker to achieve remote code execution. This is a classic example of why input validation and secure deserialization practices are non-negotiable for internet-facing services. An attacker with a foothold on your network could leverage this to move laterally and gain complete control. Are you regularly scanning your Exchange servers for such critical flaws? Proactive vulnerability assessment is key. https://nvd.nist.gov/vuln/detail/CVE-2023-21529 #XHack #cybersecurity #infosec

    Post summary

    The post highlights a critical deserialization RCE in Microsoft Exchange (CVE-2023-21529) with technical details but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000044
    31 followersView on X
  • CiberPlaneta@CiberPlanetaOrg
    Disclosure

    🛡️ CVE-2023-21529: Vulnerabilidad Crítica de Deserialización en Microsoft Exchange Server Análisis técnico de CVE-2023-21529, una vulnerabilidad de deserialización en Microsoft Exchange Server que permite ejecución remota de código. Impacto, mitigaci https://www.ciberplaneta.org/vulnerabilidades/cve-2023-21529-vulnerabilidad-critica-de-deserializacion-en-microsoft-exchange-server/ #ciberplaneta #vulnerabilidades #cve_2023_21529 #cve #vulnerabilidad #microsoft #seguridad #infosec #ciberseguridad

    Post summary

    A short technical announcement of CVE‑2023‑21529, describing it as a critical deserialization flaw in Microsoft Exchange Server that permits remote code execution, but with no PoC, exploit, or patch references.

    0000042
    6 followersView on X
  • CiberPlaneta@CiberPlanetaOrg
    Patch

    🛡️ Alerta de Seguridad: Vulnerabilidad de Deserialización de Datos No Confiables en Microsoft Exchange Server (CVE-2023-21529) Microsoft Exchange Server sufre una vulnerabilidad de deserialización de datos no confiables (CWE-502) que permite ejecución remota de código (RCE) a atacantes autenticados. CVSS 8.8 (Alta). Aplicar parches según instrucciones del proveedor y BOD 22-01 para servicios en la nube. https://www.ciberplaneta.org/boletines/90/ #ciberplaneta #bulletin #cybersecurity #cve #microsoft #exchange_server #ioc #infosec #ciberseguridad

    Post summary

    The notice highlights a CVSS 8.8 RCE vulnerability in Microsoft Exchange Server (CVE‑2023‑21529) and advises users to apply vendor patches per BOD 22‑01.

    0000049
    6 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers chaining Microsoft Exchange Server deserialization exploits (CVE-2023-21529) with Windows privilege escalation vulnerabilities for lateral movement campaigns. Runtime segmentation helps contain post-compromise activity across cloud workloads. #CloudSecurity :link: Full breakdown: https://aviatrix.ai/threat-research-center/cisa-adds-seven-known-exploited-vulnerabilities-to-catalog

    Post summary

    The tweet reports that attackers are actively exploiting Microsoft Exchange Server CVE-2023-21529 in real-world campaigns, chaining it with Windows privilege escalation for lateral movement.

    0000059
    1.9K followersView on X
  • ScyScan@ScyScan
    Active Exploitation

    Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2023-21529 #Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability https://www.scyscan.com/cve-2023-21529/microsoft-exchange-server-deserialization-of-untrusted-data-vulnerability/

    Post summary

    CVE-2023-21529, a Microsoft Exchange Server deserialization vulnerability, is reported as a known exploited vulnerability (#KEV), indicating active exploitation in the wild, but no PoC, exploit code, patch, or detailed technical information is provided.

    0000056
    61 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_server2013--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--

Explore more