References https://www.zoemurmure.top/posts/cve_2023_21554/ https://avd.aliyun.com/detail?id=AVD-2025-53144 https://www.sxxdckj.com/cms/a/Microsoft-Message-Queuing-yuan-cheng-dai-ma-zhi-xing-lou-dong.html https://rivers.chaitin.cn/blog/cq94tc10lnechd2448hg https://bbs.kafan.cn/thread-2254698-1-1.html https://avd.aliyun.com/detail?id=AVD-2023-35349 https://cloud.tencent.com/developer/article/2611318 https://www.datacomm.com/feed-post/cve-2026-34329-microsoft-message-queuing-msmq-remote-code-execution-vulnerability/ https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21554 https://www.sentinelone.com/vulnerability-database/cve-2023-32057/ https://www.broadcom.com/support/security-center/protection-bulletin/cve-2024-30080-microsoft-message-queuing-msmq-remote-code-execution-vulnerability https://www.tenable.com/plugins/nessus/175373 https://cert.europa.eu/publications/security-advisories/2023-023/pdf https://www.threatdown.com/blog/patch-now-critical-rce-vulnerability-in-microsoft-message-queuing/ https://medium.com/aardvark-infinity/security-advisory-microsoft-message-queuing-msmq-remote-code-execution-vulnerability-41f33c371365 https://businessinsights.bitdefender.com/technical-advisory-unauthorized-rce-vulnerability-in-msmq-service-cve-2023-21554-aka-queuejumper https://cve.imfht.com/detail/CVE-2025-50177?lang=en https://www.thezdi.com/blog/2026/5/12/the-may-2026-security-update-review https://www.rapid7.com/blog/post/em-patch-tuesday-may-2026/
Related VulnerabilitiesPoCCVE-2026-8237: Concrete CMS <= 9.5.0 - Unauthenticated Conversation Message Disclosure (IDOR)PoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)研華科技|Hospital Queuing Management - 存在2個漏洞Ivanti Sentry /mics/api/v2/sentry/mics-config/handleMessage 命令执行漏洞(CVE-2026-10520)智联云采 SRM2.0 /a/sys/sysMessage/statusList SQL 注入漏洞PoCretool-postmessage-xss: Retool Self-Hosted - postMessage XSS via Custom Component CollectionsPoC孚盟云CRM /m/Dingding/Ajax/AjaxFormDefault.ashx sendProductMessage SQL 注入漏洞PoC蓝凌-EIS智慧协同平台 /third/DingTalk/Pages/DingTalkMessage.aspx SQL 注入漏洞PoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)