Multiple Remote Code Execution Vulnerabilities in Microsoft Exchange and Other Systems

Multiple Remote Code Execution Vulnerabilities in Microsoft Exchange and Other Systems

First seen 17 Jun 2026, 09:43 UTC attackerkb.com 83% similarity 72.5

Article Content

Browse articles
ThreatCluster

A series of remote code execution (RCE) vulnerabilities have been identified in various systems, notably Microsoft Exchange and Fortra's GoAnywhere MFT. CVE-2020-16875 and CVE-2020-17132 affect Microsoft Exchange, allowing attackers to execute arbitrary code with authenticated user access. CVE-2020-2021 in PAN-OS permits unauthenticated network-based attackers to exploit SAML authentication weaknesses. Additionally, CVE-2023-0669 in GoAnywhere MFT allows pre-authentication command injection, while CVE-2020-28188 in TerraMaster TOS enables RCE via OS command injection. These vulnerabilities have been patched, but active exploitation remains a concern for systems still vulnerable. Security professionals are urged to apply updates and monitor for signs of exploitation.

Key Points: • Microsoft Exchange vulnerabilities allow RCE with authenticated user access. • CVE-2020-2021 enables unauthenticated access to protected resources in PAN-OS. • Fortra's GoAnywhere MFT and TerraMaster TOS also have critical RCE vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2020-06-29
CVE-2020-2021 published
PAN-OS SAML authentication bypass vulnerability disclosed, affecting unauthenticated access.
Article 2
2020-09-11
CVE-2020-16875 published
Remote code execution vulnerability in Microsoft Exchange due to cmdlet argument validation issues.
Article 1
2020-12-09
CVE-2020-17132 published
Microsoft Exchange remote code execution vulnerability disclosed, allowing exploitation by authenticated users.
Article 7
2020-12-24
CVE-2020-28188 published
TerraMaster TOS RCE vulnerability disclosed, allowing OS command injection by unauthenticated attackers.
Article 5
2021-06-08
CVE-2021-1675 published
Windows Print Spooler remote code execution vulnerability disclosed, affecting multiple Windows versions.
Article 6
Recent
Active exploitation reported
Ongoing exploitation attempts of these vulnerabilities have been observed, highlighting the need for immediate patching.
Article 3

Community

Browse all →