References https://support.microsoft.com/zh-cn/topic/%E9%80%82%97%E7%94%A8%E4%BA%8E-microsoft-exchange-server-2019-%E5%92%8C-2016-%E5%AE%89%E5%85%A8%E6%9B%B4%E6%96%B0%E7%89%88%E6%9C%AC-2-%E7%9A%84%E8%AF%B4%E6%98%8E-2023-%E5%B9%B4-8-%E6%9C%88-15-%E6%97%A5-kb5030524-940cdc34-07c4-441e-b0f4-c5a19779d715 https://www.thezdi.com/blog/2024/9/11/exploiting-exchange-powershell-after-proxynotshell-part-2-approvedapplicationcollection https://www.rapid7.com/blog/post/2023/09/12/patch-tuesday-september-2023/ https://www.tenablecloud.cn/plugins/nessus/181309 https://www.cnvd.org.cn/flaw/show/CNVD-2023-72225 https://blog.nsfocus.net/microsoftsept/ https://www.akamai.com/zh/blog/security-research/akamai-perspective-patch-tuesday-september-2023 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36756 https://nvd.nist.gov/vuln/detail/cve-2023-36756 https://www.zerodayinitiative.com/advisories/ZDI-23-1419/ https://www.cve.org/CVERecord?id=CVE-2023-36756 https://github.com/advisories/GHSA-wp99-xcpc-rj24 https://advisories.checkpoint.com/defense/advisories/public/2023/cpai-2023-0614.html https://isc.sans.edu/diary/30214 https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-exchange-server-report/
Related VulnerabilitiesCuteHttpFileServer/chfs存在未授权任意文件上传北京亿赛通科技发展有限责任公司电子文档安全管理系统CDGServer3-client存在前台sql漏洞PoCCVE-2026-42596: Gotenberg < 8.31.0 - Server-Side Request ForgeryPoCCVE-2026-45695: Kopia Server 0.23.0 - Remote Code ExecutionPoCCVE-2017-7504: JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java DeserializationPoCCVE-2026-23536: Feast Feature Server <=0.58.0 - Arbitrary File ReadPoCCVE-2026-76904: GeoServer jsonArrayContains CQL Filter - SQL Injection網韻資訊|NewSiteServer (NSS) 新式校園網站系統 - Missing Authentication網韻資訊|NewSiteServer (NSS)新式校園網站系統 - Arbitrary File UploadPoCCVE-2026-35037: Ech0 < 4.2.8 - Server-Side Request ForgeryPoCCVE-2026-32255: Kan <= 0.5.4 - Server-Side Request ForgeryPoCgeoserver-jsonarraycontains-sqli: GeoServer jsonArrayContains CQL Filter - SQL InjectionPoCibm-websphere-ssrf: IBM WebSphere HCL Digital Experience - Server-Side Request Forgery