logo

CISA Warns of Microsoft Exchange and Windows CLFS Flaws Exploited in Attacks

ID: e1dc2072-7c5b-595b-9b72-1f388e006980

STIX ID: report--e1dc2072-7c5b-595b-9b72-1f388e006980

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-04-14

Date Updated: 2026-04-14

Author: AnuPriya

...
...

CISA issued an urgent alert that two Microsoft flaws—CVE-2023-36424 (Windows CLFS out-of-bounds read enabling local privilege escalation) and CVE-2023-21529 (Exchange deserialization leading to remote code execution)—were added to the Known Exploited Vulnerabilities catalog after being observed in real-world attacks against government and enterprise networks; agencies and organizations are urged to apply patches or discontinue vulnerable products immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.