AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence93%
Public exploitation · VTP factKEV
Assessment
CISA KEV lists this Exchange Server vulnerability as exploited globally. It can enable remote code execution on affected Exchange Server installations.
Why it matters
Exchange servers process organizational email and often hold high-value data.
CISA KEV records known ransomware campaign use.
Evidence
1 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
A recent press item is not relevant to this CVE and does not establish current exploitation.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
If you run affected Exchange Server releases, apply Microsoft remediation and restrict unnecessary external access.
AI baseline history (4)
BASELINE ASSESSED
Microsoft Exchange Server remote code executiongpt-5.6-terra · low
BASELINE ASSESSED
Microsoft Exchange Server remote code executiongpt-5.6-terra · low
BASELINE ASSESSED
Microsoft Exchange Server remote code executiongpt-5.6-terra · low
BASELINE ASSESSED
Microsoft Exchange Server remote code executiongpt-5.6-sol · high
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence64%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
CISA KEV lists this vulnerability as known to be exploited globally.
02
EPSS is 1.00; this is predictive context, not exploitation evidence.
03
Exploitation attempts against this CVE were confirmed by first-party telemetry.
04
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
KEV ADDEDCISA KEV entry added
03
Claim provenance
Evidence and source independence
2publications detected
2underlying evidence chains
0 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.
00:0003 Nov
KEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
05
Original publications
Source record
The Hacker NewsPRESSUNKNOWN
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.