Microsoft Exchange Server vulnerabilities
219 known vulnerabilities affecting microsoft/exchange_server.
Total CVEs
219
CISA KEV
20
actively exploited
Public exploits
46
Exploited in wild
29
Severity breakdown
CRITICAL25HIGH89MEDIUM99LOW6
Vulnerabilities
Page 6 of 11
CVE-2026-55006P3HIGHCVSS 7.8v2016-cumulative_update_23v2019-cumulative_update_14+1 more2026-07-14
CVE-2026-55006 [HIGH] CWE-1220 CVE-2026-55006: Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacke
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2019-1136P3HIGHCVSS 8.1v2010v20132019-07-15
CVE-2019-1136 [HIGH] CVE-2019-1136: An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0692P3HIGHCVSS 8.1v2013v2016+1 more2020-02-11
CVE-2020-0692 [HIGH] CVE-2020-0692: An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
nvd
CVE-2016-3378P3HIGHCVSS 7.4v2013v20162016-09-14
CVE-2016-3378 [HIGH] CWE-20 CVE-2016-3378: Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 C
Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "Microsoft Exchange Open Redirect Vulnerability."
nvd
CVE-2025-33051P3HIGHCVSS 7.5v2016v2016-cumulative_update_1+35 more2025-08-12
CVE-2025-33051 [HIGH] CWE-200 CVE-2025-33051: Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an un
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2021-31198P3HIGHCVSS 7.8v2013v2016+1 more2021-05-11
CVE-2021-31198 [HIGH] CWE-20 CVE-2021-31198: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2019-0686P3HIGHCVSS 7.4v2010v2013+2 more2019-03-05
CVE-2019-0686 [HIGH] CVE-2019-0686: An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724.
nvd
CVE-2022-24516P3HIGHCVSS 8.0v2013v2016+1 more2022-08-09
CVE-2022-24516 [HIGH] CVE-2022-24516: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
nvd
CVE-2022-24477P3HIGHCVSS 8.0v2013v2016+1 more2022-08-09
CVE-2022-24477 [HIGH] CVE-2022-24477: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
nvd
CVE-2026-45502P3MEDIUMCVSS 5.0v2016-cumulative_update_23v2019-cumulative_update_14+1 more2026-06-09
CVE-2026-45502 [MEDIUM] CWE-918 CVE-2026-45502: Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to dis
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2017-11932P3HIGHCVSS 8.1v20162017-12-12
CVE-2017-11932 [HIGH] CWE-20 CVE-2017-11932: Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerabi
Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka "Microsoft Exchange Spoofing Vulnerability".
nvd
CVE-2022-21980P3HIGHCVSS 8.0v2013v2016+1 more2022-08-09
CVE-2022-21980 [HIGH] CVE-2022-21980: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
nvd
CVE-2010-0025P3MEDIUMCVSS 5.0v2000v2003+2 more2010-04-14
CVE-2010-0025 [MEDIUM] CWE-200 CVE-2010-0025: The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 G
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command, a
nvd
CVE-1999-0385P3CRITICALCVSS 10.0v5.51998-12-01
CVE-1999-0385 [CRITICAL] CWE-120 CVE-1999-0385: The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduc
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
nvd
CVE-2002-0698P3HIGHCVSS 7.5v5.52002-08-12
CVE-2002-0698 [HIGH] CWE-120 CVE-2002-0698: Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote att
Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow in IMC's hello response.
nvd
CVE-2021-41348P3HIGHCVSS 8.0v2016v20192021-10-13
CVE-2021-41348 [HIGH] CWE-269 CVE-2021-41348: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
nvd
CVE-2007-0220P3MEDIUMCVSS 6.8v2000v20032007-05-08
CVE-2007-0220 [MEDIUM] CWE-79 CVE-2007-0220: Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 20
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
nvd
CVE-2023-21763P3HIGHCVSS 7.8v2016v20192023-01-10
CVE-2023-21763 [HIGH] CWE-426 CVE-2023-21763: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
nvd
CVE-2022-41123P3HIGHCVSS 7.8v2016v20192022-11-09
CVE-2022-41123 [HIGH] CVE-2022-41123: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
nvd
CVE-2023-21764P3HIGHCVSS 7.8v2016v20192023-01-10
CVE-2023-21764 [HIGH] CWE-426 CVE-2023-21764: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
nvd