CVE-2023-21529
Known exploited · CISA KEV
CVSS 8.8 HIGH: microsoft Exchange Server Remote Code Execution Vulnerability EPSS 59% (99th percentile).
CISA federal remediation date Apr 27
Vulnerabilities & Exploits · Ransomware
Attackers are exploiting Microsoft vulnerabilities, including one patched nearly 14 years ago, showing that federal systems may still run legacy or unpatched software. This reuse of old flaws reveals gaps in patch management that standard responses often overlook.
CISA added four Microsoft vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch them within two weeks. These include recent privilege escalation and remote code execution flaws in Windows and Exchange Server, plus a 2012 Visual Basic for Applications vulnerability still actively exploited.
The persistence of attacks leveraging a 2012 vulnerability signals that legacy software remains a critical risk. This trend suggests that patching alone is insufficient if older systems or updates are neglected, leaving federal networks vulnerable to ransomware and data theft.
1 source · Apr 13
Known exploited · CISA KEV
CVSS 8.8 HIGH: microsoft Exchange Server Remote Code Execution Vulnerability EPSS 59% (99th percentile).
CISA federal remediation date Apr 27
Known exploited · CISA KEV
CVSS 7.8 HIGH: untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and… EPSS 21% (97th percentile).
CISA federal remediation date Apr 27
Known exploited · CISA KEV
CVSS 7.8 HIGH: windows Common Log File System Driver Elevation of Privilege Vulnerability EPSS 12% (96th percentile).
CISA federal remediation date Apr 27
Known exploited · CISA KEV
CVSS 7.8 HIGH: improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized… EPSS 5% (91st percentile).
CISA federal remediation date Apr 27
The Register Security
Ransomware scum, other crims exploit 4 old Microsoft bugs
: One was patched almost 14 years ago
originalPart of the PlainSec briefing for 2026-04-14
Every edition of this story: Federal Systems Still Exposed to Decade-Old Microsoft Vulnerabilities