← Threat Center
8.8
HIGH • CVSS 3.1

CVE-2023-21529

CISA KNOWN EXPLOITED

Microsoft Exchange Server Remote Code Execution Vulnerability

Prioritization

NVD CVSS
8.8
Published
Feb 14, 2023 3:15 PM EST
Modified
Aug 19, 2026 1:18 PM EDT
CISA KEV
Yes
KEV due date
2026-04-27
CISA required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Red Hat context

No Red Hat-specific cached context is available for this record.

DEFENSIVE REMEDIATION WORKFLOW

Recommended response

  1. Treat as priority because it appears in CISA Known Exploited Vulnerabilities data; follow the required action and due date where applicable.
  2. Identify affected assets with Qualys, Tanium, software inventory, CMDB or configuration-management data.
  3. Confirm package/application applicability before change execution; CVSS alone does not prove that every host is vulnerable.
  4. Patch, upgrade, rehydrate or apply a vendor-approved mitigation through controlled change. GraceITS can automate eligible waves with Ansible/Tanium.
  5. Rescan after remediation and reconcile remaining exceptions, false positives, unsupported systems and compensating controls.