Netskope Threat Labs

SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt

IPS-NPA

13 SIDs: 60642, 60670, 60671, 60672, 60673, 60674, 60675, 60676, 60677, 60678, 61042, 61359, 61360

First seen
November 2025
Last seen
April 2026

Detects an attempt to exploit CVE-2022-41040, CVE-2022-41080, CVE-2022-41082, and 2 others, a remote code execution flaw that can run code on the server in Microsoft Exchange Server.