logo

CISA Warns of Microsoft Exchange and Windows CLFS Vulnerabilities Exploited in Attacks

ID: 94fa0148-dce2-5cb7-a3b4-ede2c3fb1bb4

STIX ID: report--94fa0148-dce2-5cb7-a3b4-ede2c3fb1bb4

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-14

Date Updated: 2026-04-21

Author: Abinaya

...
...

CISA issued an urgent advisory warning that threat actors are actively exploiting two severe Microsoft flaws — CVE-2023-21529 (Exchange Server RCE via deserialization) and CVE-2023-36424 (Windows CLFS local out-of-bounds read enabling privilege escalation). Both vulnerabilities were added to CISA’s Known Exploited Vulnerabilities catalog; federal agencies must apply available patches by April 27, 2026, and private organizations are strongly urged to prioritize remediation and monitor affected Exchange and Windows environments for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.