Microsoft Exchange Server vulnerabilities
219 known vulnerabilities affecting microsoft/exchange_server.
Total CVEs
219
CISA KEV
20
actively exploited
Public exploits
46
Exploited in wild
29
Severity breakdown
CRITICAL25HIGH89MEDIUM99LOW6
Vulnerabilities
Page 4 of 11
CVE-2026-45504P3HIGHCVSS 8.8v2016-cumulative_update_23v2019-cumulative_update_14+1 more2026-06-09
CVE-2026-45504 [HIGH] CWE-918 CVE-2026-45504: Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to ele
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2024-26198P3HIGHCVSS 8.8v2016v20192024-03-12
CVE-2024-26198 [HIGH] CWE-426 CVE-2024-26198: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2023-38185P3HIGHCVSS 8.8v2016v20192023-08-08
CVE-2023-38185 [HIGH] CWE-23 CVE-2023-38185: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2020-17084P3HIGHCVSS 8.8v2013v2016+1 more2020-11-11
CVE-2020-17084 [HIGH] CWE-120 CVE-2020-17084: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2009-0098P3CRITICALCVSS 9.3v2000v2003+1 more2009-02-10
CVE-2009-0098 [CRITICAL] CWE-399 CVE-2009-0098: Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not pr
Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
nvd
CVE-2006-0002P3HIGHCVSS 7.5v5.0v5.5+1 more2006-01-10
CVE-2006-0002 [HIGH] CVE-2006-0002: Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
nvd
CVE-2023-21709P3CRITICALCVSS 9.8v2016v20192023-08-08
CVE-2023-21709 [CRITICAL] CWE-307 CVE-2023-21709: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
nvd
CVE-2023-36777P3MEDIUMCVSS 5.7v2016v20192023-09-12
CVE-2023-36777 [MEDIUM] CWE-502 CVE-2023-36777: Microsoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server Information Disclosure Vulnerability
nvd
CVE-2023-35388P3HIGHCVSS 8.0v2016v20192023-08-08
CVE-2023-35388 [HIGH] CWE-502 CVE-2023-35388: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2004-0840P3CRITICALCVSS 10.0v20032004-11-03
CVE-2004-0840 [CRITICAL] CWE-20 CVE-2004-0840: The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows S
The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly val
nvd
CVE-2020-17142P3CRITICALCVSS 9.1v2013v2016+1 more2020-12-10
CVE-2020-17142 [CRITICAL] CVE-2020-17142: Microsoft Exchange Remote Code Execution Vulnerability
Microsoft Exchange Remote Code Execution Vulnerability
nvd
CVE-2023-35368P3HIGHCVSS 8.8v2016v20192023-08-08
CVE-2023-35368 [HIGH] CWE-20 CVE-2023-35368: Microsoft Exchange Remote Code Execution Vulnerability
Microsoft Exchange Remote Code Execution Vulnerability
nvd
CVE-2023-38182P3HIGHCVSS 8.0v2016v20192023-08-08
CVE-2023-38182 [HIGH] CWE-502 CVE-2023-38182: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2005-0044P3HIGHCVSS 7.5v5.02005-05-02
CVE-2005-0044 [HIGH] CVE-2005-0044: The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, do
The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."
nvd
CVE-2026-45583P3HIGHCVSS 8.1v2016-cumulative_update_23v2019-cumulative_update_14+1 more2026-06-09
CVE-2026-45583 [HIGH] CWE-94 CVE-2026-45583: Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an una
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-64666P3HIGHCVSS 7.5v2016v2016-cumulative_update_1+35 more2025-12-09
CVE-2025-64666 [HIGH] CWE-20 CVE-2025-64666: Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate priv
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2018-8265P3HIGHCVSS 7.8v2013-cumulative_update_21v2016-cumulative_update_102018-10-10
CVE-2018-8265 [HIGH] CWE-20 CVE-2018-8265: A remote code execution vulnerability exists in the way Microsoft Exchange software parses specially
A remote code execution vulnerability exists in the way Microsoft Exchange software parses specially crafted email messages, aka "Microsoft Exchange Remote Code Execution Vulnerability." This affects Microsoft Exchange Server.
nvd
CVE-2005-0420P4MEDIUMCVSS 5.8PoCv20032005-04-27
CVE-2005-0420 [MEDIUM] CWE-601 CVE-2005-0420: Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect use
Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.
nvd
CVE-2018-16793P3HIGHCVSS 8.6v20102018-09-21
CVE-2018-16793 [HIGH] CWE-918 CVE-2018-16793: Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via
Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.
nvd
CVE-2021-26427P3CRITICALCVSS 9.6v2013v2016+1 more2021-10-13
CVE-2021-26427 [CRITICAL] CVE-2021-26427: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd