cbcvebase.

Microsoft Exchange Server vulnerabilities

219 known vulnerabilities affecting microsoft/exchange_server.

Total CVEs
219
CISA KEV
20
actively exploited
Public exploits
46
Exploited in wild
29
Severity breakdown
CRITICAL25HIGH89MEDIUM99LOW6

Vulnerabilities

Page 3 of 11
CVE-2021-26412P2HIGHCVSS 7.2PoCv2013v2016+1 more2021-03-03
CVE-2021-26412 [HIGH] CVE-2021-26412: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2021-26854P2HIGHCVSS 7.2PoCv2013v2016+1 more2021-03-03
CVE-2021-26854 [HIGH] CVE-2021-26854: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2021-27078P2HIGHCVSS 7.2PoCv2013v2016+1 more2021-03-03
CVE-2021-27078 [HIGH] CVE-2021-27078: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2003-0714P3HIGHCVSS 7.5PoCv5.5v20002003-11-17
CVE-2003-0714 [HIGH] CWE-400 CVE-2003-0714: The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.
nvd
CVE-2023-36744P2HIGHCVSS 8.0v2016v20192023-09-12
CVE-2023-36744 [HIGH] CWE-502 CVE-2023-36744: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2020-17143P2HIGHCVSS 8.8v2013v2016+1 more2020-12-10
CVE-2020-17143 [HIGH] CVE-2020-17143: Microsoft Exchange Server Information Disclosure Vulnerability Microsoft Exchange Server Information Disclosure Vulnerability
nvd
CVE-2023-36756P2HIGHCVSS 8.0v2016v20192023-09-12
CVE-2023-36756 [HIGH] CWE-502 CVE-2023-36756: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2019-1373P2CRITICALCVSS 9.8v2013v2016+1 more2019-11-12
CVE-2019-1373 [CRITICAL] CWE-502 CVE-2019-1373: A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of me A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.
nvd
CVE-2018-8302P2CRITICALCVSS 9.8v2010-sp3v2013-cumulative_update_20+3 more2018-08-15
CVE-2018-8302 [CRITICAL] CWE-787 CVE-2018-8302: A remote code execution vulnerability exists in Microsoft Exchange software when the software fails A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.
nvd
CVE-2020-17117P2HIGHCVSS 7.2v2013v2016+1 more2020-12-10
CVE-2020-17117 [HIGH] CVE-2020-17117: Microsoft Exchange Remote Code Execution Vulnerability Microsoft Exchange Remote Code Execution Vulnerability
nvd
CVE-2018-8154P2CRITICALCVSS 9.8v2010-sp3v2013-cumulative_update_19+4 more2018-05-09
CVE-2018-8154 [CRITICAL] CVE-2018-8154: A remote code execution vulnerability exists in Microsoft Exchange software when the software fails A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151.
nvd
CVE-2019-0586P2CRITICALCVSS 9.8v2016-cumulative_update_10v2016-cumulative_update_11+1 more2019-01-08
CVE-2019-0586 [CRITICAL] CWE-787 CVE-2019-0586: A remote code execution vulnerability exists in Microsoft Exchange software when the software fails A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.
nvd
CVE-2025-59249P2HIGHCVSS 8.8v2016v2016-cumulative_update_1+35 more2025-10-14
CVE-2025-59249 [HIGH] CWE-1390 CVE-2025-59249: Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-55005P2HIGHCVSS 8.8v2016-cumulative_update_23v2019-cumulative_update_14+1 more2026-07-14
CVE-2026-55005 [HIGH] CWE-122 CVE-2026-55005: Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute cod Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
nvd
CVE-2008-1547P4MEDIUMCVSS 4.3PoCv20032008-10-21
CVE-2008-1547 [MEDIUM] CWE-601 CVE-2008-1547: Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Excha Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.
nvd
CVE-2023-28310P3HIGHCVSS 8.0v2016v20192023-06-14
CVE-2023-28310 [HIGH] CWE-502 CVE-2023-28310: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2017-8537P3MEDIUMCVSS 5.5PoCv2013v20162017-05-26
CVE-2017-8537 [MEDIUM] CVE-2017-8537: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Mic The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially c
nvd
CVE-2017-8536P3MEDIUMCVSS 5.5PoCv2013v20162017-05-26
CVE-2017-8536 [MEDIUM] CVE-2017-8536: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Mic The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially c
nvd
CVE-2017-8535P3MEDIUMCVSS 5.5PoCv2013v20162017-05-26
CVE-2017-8535 [MEDIUM] CWE-119 CVE-2017-8535: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Mic The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a spe
nvd
CVE-2023-21706P2HIGHCVSS 8.8v2013v2016+1 more2023-02-14
CVE-2023-21706 [HIGH] CWE-502 CVE-2023-21706: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
Microsoft Exchange Server vulnerabilities | cvebase