Multiple Microsoft Exchange Server RCE Flaws Patched Across Supported Releases
Microsoft published security advisories for several Microsoft Exchange Server remote code execution vulnerabilities, including CVE-2021-26427, CVE-2022-21969, CVE-2022-23277, and CVE-2023-36778. The flaws affect on-premises Exchange Server deployments and were addressed through Microsoft's Security Update Guide, indicating a recurring pattern of high-impact code-execution risk in a core enterprise messaging platform.
The advisories show Microsoft issuing fixes over multiple release cycles for distinct Exchange Server RCE bugs rather than a single isolated defect. For defenders, the immediate implication is to verify that all supported Exchange Server instances have the relevant cumulative and security updates applied, because unpatched mail servers remain a high-value target due to their internet exposure, privileged position in enterprise environments, and history of exploitation by threat actors.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft discloses CVE-2023-36778 in Exchange Server
Microsoft added CVE-2023-36778 to its Security Update Guide as a remote code execution vulnerability affecting Microsoft Exchange Server.
Microsoft discloses CVE-2022-23277 in Exchange Server
Microsoft published Security Update Guide information for CVE-2022-23277, a remote code execution vulnerability impacting Microsoft Exchange Server.
Microsoft discloses CVE-2022-21969 in Exchange Server
Microsoft released a Security Update Guide advisory for CVE-2022-21969, identifying it as a remote code execution vulnerability in Microsoft Exchange Server.
Microsoft discloses CVE-2021-26427 in Exchange Server
Microsoft published security guidance for CVE-2021-26427, a remote code execution vulnerability affecting Microsoft Exchange Server.
Sources
4 references tracked. Mallory keeps watching after this page renders.
CVE-2023-36778 - Security Update Guide - Microsoft - Microsoft Exchange Server Remote Code Execution Vulnerability
msrc.microsoft.com
Open sourceCVE-2022-23277 - Security Update Guide - Microsoft - Microsoft Exchange Server Remote Code Execution Vulnerability
msrc.microsoft.com
Open sourceCVE-2022-21969 - Security Update Guide - Microsoft - Microsoft Exchange Server Remote Code Execution Vulnerability
portal.msrc.microsoft.com
Open sourceCVE-2021-26427 - Security Update Guide - Microsoft - Microsoft Exchange Server Remote Code Execution Vulnerability
msrc.microsoft.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


