logo

Microsoft Exchange Vulnerabilities CVE-2020-16875 and CVE-2023-23397 Under Active Exploitation

ID: c0f9a02c-fda4-512c-9785-388ad6c2b94d

STIX ID: report--c0f9a02c-fda4-512c-9785-388ad6c2b94d

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-17

Date Updated: 2026-06-22

...
...

The report describes two Microsoft vulnerabilities — CVE-2020-16875 (an authenticated RCE in Exchange Server allowing SYSTEM-level code execution) and CVE-2023-23397 (a zero-interaction Outlook vulnerability confirmed to be actively exploited and potentially linked to nation-state actors) — and urges organizations to apply patches and mitigations immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.