Microsoft Exchange Server

29 known vulnerabilities in Microsoft Exchange Server, 6 critical, 19 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-42897 CVSS 6.1 medium · actively exploited Microsoft Exchange Server Cross-Site Scripting Vulnerability
  • CVE-2024-21410 CVSS 9.8 critical · actively exploited Microsoft Exchange Server Privilege Escalation Vulnerability
  • CVE-2023-21529 CVSS 8.8 high · actively exploited Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
  • CVE-2022-41080 CVSS 8.8 high · actively exploited Microsoft Exchange Server Privilege Escalation Vulnerability
  • CVE-2022-41082 CVSS 8.0 high · actively exploited Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2022-41040 CVSS 8.8 high · actively exploited Microsoft Exchange Server Server-Side Request Forgery Vulnerability
  • CVE-2021-42321 CVSS 8.8 high · actively exploited Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2021-34523 CVSS 9.0 critical · actively exploited Microsoft Exchange Server Privilege Escalation Vulnerability
  • CVE-2021-34473 CVSS 9.1 critical · actively exploited Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2021-33766 CVSS 7.3 high · actively exploited Microsoft Exchange Server Information Disclosure

Latest vulnerabilities

  • CVE-2026-96940 CVSS 8.8 high Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
  • CVE-2026-69641 CVSS 9.1 critical Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
  • CVE-2026-69382 CVSS 5.9 medium Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over…
  • CVE-2026-69380 CVSS 8.1 high Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
  • CVE-2026-69378 CVSS 7.5 high Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
  • CVE-2026-69375 CVSS 6.5 medium Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a…
  • CVE-2026-69361 CVSS 6.5 medium Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
  • CVE-2026-69356 CVSS 9.3 critical Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized…
  • CVE-2026-69355 CVSS 8.8 high External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
  • CVE-2026-55007 CVSS 8.1 high Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
  • CVE-2026-42897 CVSS 6.1 medium · actively exploited Microsoft Exchange Server Cross-Site Scripting Vulnerability
  • CVE-2024-21410 CVSS 9.8 critical · actively exploited Microsoft Exchange Server Privilege Escalation Vulnerability
  • CVE-2023-21529 CVSS 8.8 high · actively exploited Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
  • CVE-2022-41080 CVSS 8.8 high · actively exploited Microsoft Exchange Server Privilege Escalation Vulnerability
  • CVE-2022-41082 CVSS 8.0 high · actively exploited Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2022-41040 CVSS 8.8 high · actively exploited Microsoft Exchange Server Server-Side Request Forgery Vulnerability
  • CVE-2021-42321 CVSS 8.8 high · actively exploited Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2021-34523 CVSS 9.0 critical · actively exploited Microsoft Exchange Server Privilege Escalation Vulnerability
  • CVE-2021-34473 CVSS 9.1 critical · actively exploited Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2021-33766 CVSS 7.3 high · actively exploited Microsoft Exchange Server Information Disclosure
  • CVE-2021-31196 CVSS 7.2 high · actively exploited Microsoft Exchange Server Information Disclosure Vulnerability
  • CVE-2021-31207 CVSS 6.6 medium · actively exploited Microsoft Exchange Server Security Feature Bypass Vulnerability
  • CVE-2021-27065 CVSS 7.8 high · actively exploited Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2021-26858 CVSS 7.8 high · actively exploited Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2021-26857 CVSS 7.8 high · actively exploited Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2021-26855 CVSS 9.1 critical · actively exploited Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2020-17144 CVSS 8.4 high · actively exploited Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2020-0688 CVSS 8.8 high · actively exploited Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability
  • CVE-2018-8581 CVSS 7.4 high · actively exploited Microsoft Exchange Server Privilege Escalation Vulnerability