CVE-2023-21529CISA KEV
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
- Product
- Exchange Server
- Added to KEV
- 13 Apr 2026
- Federal remediation due
- 27 Apr 2026
- Known ransomware use
- Yes