CVE-2023-21529: Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2026-04-13. EPSS: 59.3% chance of exploitation in the next 30 days.

Microsoft Exchange Server Remote Code Execution Vulnerability

Affected products

  • Microsoft Exchange Server: version 2013 only; version 2016 only; version 2019 only

Published 2023-02-14. Last modified 2026-08-19.