AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence94%
Public exploitation · VTP factKEV
Assessment
This network-reachable Exchange Server remote-code-execution vulnerability is listed in CISA KEV and associated there with known ransomware campaign use.
Why it matters
Successful exploitation can cause high confidentiality and integrity impact without user interaction.
CVSS 9.1 and EPSS 0.99999 provide critical technical and predictive context.
Evidence
0 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
No exploit artifact, exploitation-chain detail, or first-party observation is supplied.
Actual affected-server exposure is unknown.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
Track the listed vulnerable Exchange 2013 and 2016 cumulative updates.
AI baseline history (1)
BASELINE ASSESSED
Microsoft Exchange Server remote code executiongpt-5.6-sol · high
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
CISA KEV lists this vulnerability as known to be exploited globally.
02
EPSS is 1.00; this is predictive context, not exploitation evidence.
03
Exploitation attempts against this CVE were confirmed by first-party telemetry.
04
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
KEV ADDEDCISA KEV entry added
03
Claim provenance
Evidence and source independence
0publications detected
0underlying evidence chains
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
04
Event history
Threat timeline
00:0003 Nov
KEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.