Microsoft Exchange Server vulnerabilities
219 known vulnerabilities affecting microsoft/exchange_server.
Total CVEs
219
CISA KEV
20
actively exploited
Public exploits
46
Exploited in wild
29
Severity breakdown
CRITICAL25HIGH89MEDIUM99LOW6
Vulnerabilities
Page 5 of 11
CVE-1999-0284P4HIGHCVSS 7.5PoCv4.0v5.01998-01-01
CVE-1999-0284 [HIGH] CWE-120 CVE-1999-0284: Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer over
Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.
nvd
CVE-2005-1987P3HIGHCVSS 7.5v20002005-10-13
CVE-2005-1987 [HIGH] CWE-120 CVE-2005-1987: Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exch
Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.
nvd
CVE-2023-21710P3HIGHCVSS 7.2v2016v20192023-02-14
CVE-2023-21710 [HIGH] CWE-502 CVE-2023-21710: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2022-21969P3CRITICALCVSS 9.0v2013v2016+1 more2022-01-11
CVE-2022-21969 [CRITICAL] CVE-2022-21969: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2021-28483P3CRITICALCVSS 9.0v2013v2016+1 more2021-04-13
CVE-2021-28483 [CRITICAL] CVE-2021-28483: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2023-36439P3HIGHCVSS 8.0v2016v20192023-11-14
CVE-2023-36439 [HIGH] CWE-502 CVE-2023-36439: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2022-21846P3CRITICALCVSS 9.0v2013v2016+1 more2022-01-11
CVE-2022-21846 [CRITICAL] CVE-2022-21846: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2022-21855P3CRITICALCVSS 9.0v2013v2016+1 more2022-01-11
CVE-2022-21855 [CRITICAL] CVE-2022-21855: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2020-17141P3HIGHCVSS 8.4v2016v20192020-12-10
CVE-2020-17141 [HIGH] CVE-2020-17141: Microsoft Exchange Remote Code Execution Vulnerability
Microsoft Exchange Remote Code Execution Vulnerability
nvd
CVE-2025-53786P3HIGHCVSS 8.0v2016-cumulative_update_23v2019-cumulative_update_14+1 more2025-08-06
CVE-2025-53786 [HIGH] CWE-287 CVE-2025-53786: On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance an
nvd
CVE-2023-36778P3HIGHCVSS 8.0v2016v20192023-10-10
CVE-2023-36778 [HIGH] CWE-426 CVE-2023-36778: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2026-55009P3HIGHCVSS 7.8v2016-cumulative_update_23v2019-cumulative_update_14+1 more2026-07-14
CVE-2026-55009 [HIGH] CWE-502 CVE-2026-55009: Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elev
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59248P3HIGHCVSS 7.5v2016v2016-cumulative_update_1+35 more2025-10-14
CVE-2025-59248 [HIGH] CWE-20 CVE-2025-59248: Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform sp
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-55008P3CRITICALCVSS 9.6v2016-cumulative_update_23v2019-cumulative_update_14+1 more2026-07-14
CVE-2026-55008 [CRITICAL] CWE-79 CVE-2026-55008: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2002-1790P4MEDIUMCVSS 5.0PoCv5.52002-12-31
CVE-2002-1790 [MEDIUM] CVE-2002-1790: The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attacker
The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.
nvd
CVE-2025-53782P3HIGHCVSS 7.8v2016v2016-cumulative_update_1+35 more2025-10-14
CVE-2025-53782 [HIGH] CWE-303 CVE-2025-53782: Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthor
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2007-0039P3HIGHCVSS 7.8v2000v2003+1 more2007-05-08
CVE-2007-0039 [HIGH] CWE-476 CVE-2007-0039: The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3,
The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which t
nvd
CVE-2010-2091P4MEDIUMCVSS 4.3PoCv20072010-05-27
CVE-2010-2091 [MEDIUM] CWE-79 CVE-2010-2091: Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is use
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
nvd
CVE-2007-0221P3HIGHCVSS 7.8v20002007-05-08
CVE-2007-0221 [HIGH] CWE-190 CVE-2007-0221: Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote att
Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."
nvd
CVE-2006-1193P4LOWCVSS 2.6PoCv20002006-06-13
CVE-2006-1193 [LOW] CWE-79 CVE-2006-1193: Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when run
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
nvd