Critical 9.8
KEV-listed
CVE-2023-23397
Exploitation of Microsoft Exchange Server Vulnerability CVE-2023-23397
Vendor / product: Microsoft Outlook
Event date: 2023-01-01
Public PoC: Yes
First tracked by RiskWire: 2026-09-25
CISA KEV catalog
Added to KEV
Federal remediation due
2023-04-04 (1270 days overdue)
Ransomware campaign use
Unknown
CISA description
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
Required action
Apply updates per vendor instructions.
Named threat actors
APT28Fancy Bear
Sources & citations (8)
- Exchange Server Exposure: 8,471 Observed Instances and a Decade of Targeted Exploitation dev.to · 2026-09-25
- Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline dev.to · 2026-09-25
- WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV thehackernews.com · 2026-09-25
- U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog securityaffairs.com · 2026-09-25
- Hackers now exploit critical Roundcube flaw in code injection attacks bleepingcomputer.com · 2026-09-24
- Roundcube Webmail Vulnerability in Attackers' Crosshairs securityweek.com · 2026-09-25
- Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication gbhackers.com · 2026-09-24
- Google Pixel Modem Flaw Under Active Exploitation Sits Below Every Security Layer tech.yahoo.com · 2026-09-25
References
See CVE-2023-23397 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →