Since March 28, 2026, two critical vulnerabilities have been publicly known that, in combination, pose a significant threat to organizations. Both CVEs are being actively exploited and have been on the CISA Known Exploited Vulnerabilities (KEV) list since March 29. This article documents the situation, the detection process and the professional incident response.
1. Situation Assessment
CVE-2026-21345 Remote Code Execution in Microsoft Exchange Server
Affected systems: Microsoft Exchange Server 2019 CU14
CVSS Score: 9.8 (Critical)
Attack vector: Unauthenticated Remote Code Execution via manipulated MAPI-over-HTTP request
PoC Status: Proof-of-Concept publicly available since 28.03.2026
The vulnerability allows an attacker to execute arbitrary code on the Exchange Server without any authentication. The exploit uses a faulty deserialization in the MAPI-over-HTTP protocol. A specially crafted POST request to the /mapi/emsmdb/ endpoint is sufficient to gain SYSTEM privileges on the server.
CVE-2026-21892 Authentication Bypass in Fortinet FortiOS SSL-VPN
Affected systems: Fortinet FortiOS 7.4.x with SSL-VPN Web-Mode enabled
CVSS Score: 9.1 (Critical)
Attack vector: Authentication Bypass unauthenticated access to VPN tunnel
When the SSL-VPN Web-Mode is enabled, attackers can completely bypass authentication and establish a VPN tunnel. This enables direct access to the internal network without valid credentials. The vulnerability is already being actively exploited by several APT groups.
Both vulnerabilities have been on the CISA KEV list since 29.03.2026. Organizations are required to patch within defined deadlines.
2. Detection & Reporting (SecMon)
Detection occurred through two parallel channels of security monitoring:
Exchange Vulnerability (Microsoft Sentinel)
- Anomalous MAPI requests with unusual content-type headers detected
- Correlation with known IoC patterns from the initial advisory
- Increased volume of POST requests to
/mapi/emsmdb/from external IPs
FortiOS Vulnerability (FortiAnalyzer)
- Unexpected session establishments without prior authentication
- SSL-VPN logins from known TOR exit nodes
- Session anomalies: VPN tunnels without corresponding auth events
Alert Chain
The standardized escalation followed the defined playbook:
- SIEM Alert → Automatic ticket creation
- SOC L1 Triage → Initial assessment, prioritization as Critical
- L2 Analysis → Confirmation of exploitation, scope assessment
- Incident Declaration → Activation of the incident response process
Indicators of Compromise (IoC)
- Specific user-agent strings in MAPI requests
- POST requests to
/mapi/emsmdb/with manipulated headers - SSL-VPN logins from TOR exit nodes without prior authentication
- Unusual processes on Exchange servers (w3wp.exe → cmd.exe chains)
MITRE ATT&CK Mapping
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1059 Command and Scripting Interpreter (Post-Exploitation)
3. Patch Management Process
Microsoft Patch: KB5036922 (Out-of-band Release, 29.03.2026)
Fortinet Patch: FortiOS 7.4.5 (Released 28.03.2026)
Rollout Strategy (Timeline)
| Timeframe | Action |
|---|---|
| Hour 0–2 | Impact assessment, identify affected systems via CMDB query |
| Hour 2–4 | Test patch in staging environment, functional and regression testing |
| Hour 4–8 | Create Emergency Change Request, obtain CAB approval |
| Hour 8–12 | Rollout to production systems (internet-exposed first) |
| Hour 12–24 | Verification, post-patch scans, functional testing |
Interim Mitigation (Before Patch Availability)
- Exchange: WAF rule for MAPI endpoint blocks suspicious content-type headers and oversized POST requests to
/mapi/emsmdb/ - FortiOS: Temporarily disable SSL-VPN Web-Mode, allow only tunnel mode with client certificate
4. Customer Communication
The structured communication follows a fixed schedule:
- Hour 0: Internal assessment Severity: Critical, all relevant teams informed
- Hour 1: First customer notification via encrypted email "Security Advisory: Critical vulnerability identified, measures initiated"
- Hour 4: Status update with specific patch schedule and interim measures
- Hour 12: Confirmation: Patch rollout started, first systems patched
- Hour 24: Final report affected systems, measures taken, verification, recommendations
Communication channels: Encrypted email (standard), customer portal (status dashboard), additional telephone notification for critical incidents.
5. Report Creation
The post-incident report follows the NIST SP 800-61r2 framework and contains:
- Executive Summary Management-level summary for executive leadership
- Technical Details Detailed technical analysis for the IT department
- Timeline Minute-by-minute documentation of the entire incident
- Affected Systems Complete inventory list of affected systems
- Actions Taken All measures carried out (patch, mitigation, monitoring adjustments)
- Lessons Learned What went well, what can be improved
- Recommendations Specific action recommendations
KPI Tracking
The performance of the incident response is measured using defined KPIs:
- Mean Time to Detect (MTTD): 23 minutes
- Mean Time to Respond (MTTR): 45 minutes
- Mean Time to Patch (MTTP): 8 hours (Exchange), 6 hours (FortiOS)
6. Assessment
At Nemonicon GmbH, this process is part of daily business. As a Managed Security Provider with SecMon, MDR and structured patch management, the team responds according to defined playbooks from detection through customer communication to a clean final report. Swiss quality means here: no patch without testing, no incident without a report, no customer without information.
The combination of automated detection, structured processes and transparent communication demonstrates how professional incident response works in practice. In an era where critical vulnerabilities are being exploited ever faster, a well-coordinated team with clear playbooks is not a luxury but a necessity.