⚡ Exploit-DB.ai HIGH
HIGH

CVE-2023-36745

Published: March 18, 2026 · Source: National Vulnerability Database (NVD)

⚡ AI Threat Assessment

Exchange Server authenticated RCE — requires Network Access + Valid Exchange Credentials. Apply September 2023 patches. Enforce MFA on all Exchange accounts to raise the exploitation bar. Monitor Exchange OAB endpoint for unusual download patterns.

📋 Official Description

Microsoft Exchange Server Remote Code Execution Vulnerability in September 2023 updates requiring authentication but enabling RCE via the OAB Download endpoint.

Get Real-Time CVE Alerts

Supernova subscribers receive AI-triaged CVE alerts the moment they're published — before the PoC drops.

Start Supernova — $99/mo →