Critical Analysis: CVE-2023-21529 - Microsoft Exchange Server Deserialization of Untrusted Data ... — April 19, 2026

Published 19 Apr 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news

Initial Discovery and Context Alright, let's carve into CVE-2023-21529: Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability. This critical deserialization flaw, published by Microsoft on April 19, 2026, hit the radar with a CVSSv3 score of 9.8, which should immediately flag it as a "drop everything" issue for anyone running Exchange. While the details emerged recently, the underlying architecture that enables such deserialization vulnerabilities has been a known quantity in our threat modeling exercises for years. This particular beast focuses on Exchange Server 2013, 2016, and 2019. The affected component is a specific internal API endpoint accessible to authenticated users – and that 'authenticated user' part is key for initial access context, though we'll get to how quickly an attacker can bypass that. The vulnerability allows for remote code execution