HIGHVulnerability
Verified
Global

CISA KEV: Microsoft Exchange Server — Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

Analysis

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. Added to CISA Known Exploited Vulnerabilities catalog on 2026-04-13. Remediation due: 2026-04-27.

Indicators of Compromise (1)

CVE (1)
CVE-2023-21529
Source Attribution

Originally published by CISA KEV on Apr 13, 2026. Verified by: CISA.

Related Threats