logo

Over 28,500 Exchange servers vulnerable to actively exploited bug

ID: 44f06ac9-c72b-5c07-848b-32a32f12c609

STIX ID: report--44f06ac9-c72b-5c07-848b-32a32f12c609

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-02-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Critical Microsoft Exchange privilege-escalation vulnerability CVE-2024-21410, which enables NTLM relay attacks and can allow attackers to escalate privileges on Exchange servers, is being actively exploited; Shadowserver identified roughly 97,000 potentially vulnerable servers (28,500 confirmed). Administrators are urged to apply Exchange Server 2019 CU14 (NTLM Relay Protections) or other mitigations; CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.