RaqibCTI
CVE

CVE-2023-21529

P1⬤ KNOWN RANSOMWARE USE
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
Microsoft · Exchange Server
Date added (CISA)
2026-04-13
Remediation due
2026-04-27
Known ransomware use
Yes
Remediation priority
P1known ransomware use · past CISA due date

Description

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

Source: NVD ↗ · CISA KEV Catalog ↗