CVE-2023-36025

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 13 articles

EPSS Score

Source: FIRST.org · 2026-05-24
91.47%
probability
This CVE has a 91.47% probability of being exploited in the next 30 days.
0% Top 99.7th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Signal Intelligence

Confidence
85%
EPSS 91.47%
Mentions 13
Last Seen Aug 13, 2024

CNA Information

Analyst Note

CVE-2023-36025 is explicitly named as a zero-day exploited in the wild since March 2023, preceding the November 2023 patch publication. Multiple authoritative sources (BleepingComputer, CERT-EU) confirm active exploitation in malware attacks before patch availability, meeting all zero-day criteria.

Threat Actors 9

APT 29
apt_group Information theft and espionage 🇷🇺 RU
Vicious Panda
apt_group Information theft and espionage 🇨🇳 CN
Evilnum
apt_group Information theft and espionage
Opal Sleet
apt_group 🇰🇵 KP
Void Banshee
apt_group unknown
TA571
apt_group 🇷🇺 RU
The White Company
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 05, 2026