KEVIntel
8.8
CVSS
High

CVE-2023-21529

PUBLISHED

Microsoft Exchange Server Remote Code Execution Vulnerability

1 day faster than CISA KEV

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Microsoft
Product
Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 23
Published
Feb 14, 2023
EPSS
27.0% · 96% pctl

Automate this intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

cisa malware microsoft

Weaknesses (CWE)

  • Deserialization of Untrusted Data

CVSS scores

CVSS v3.1 8.8 High

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2026-06-01 13:07:10 UTC · CVE

Used in malware

Recorded 2026-06-02 14:02:11 UTC · CVE

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE First 2026-06-01 13:07 UTC
CISA 2026-06-02 14:02 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • KEV confirmed by CISA

  • Exploit Used in Malware