Vulnerability intelligence
CVE-2020-0688
Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability
Microsoft Exchange Server
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
CVSS Score
8.8
High
EPSS — Exploit Probability
100%
Riskier than 100% of all CVEs · checked 2026-09-21
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
unknown
Federal deadline 2022-05-03
CISA required action
Apply updates per vendor instructions. Deadline for federal agencies: 2022-05-03.
1 article across 1 outlet · first covered Sep 21, 2026 · latest Sep 21, 2026
Associated threat actors
Coverage timeline
-
NightEagle Hackers Target Russian Firms With GhostContainer Backdoorsecurityonline.info · Sep 21, 2026