Exchange Server
by Microsoft
CVEs (259)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-35368 | Hig | 0.57 | 8.8 | 0.02 | Aug 8, 2023 | Microsoft Exchange Remote Code Execution Vulnerability | ||
| CVE-2018-16793 | Hig | 0.57 | 8.6 | 0.11 | Sep 21, 2018 | Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page. | ||
| CVE-2020-17084 | Hig | 0.56 | 8.5 | 0.04 | Nov 11, 2020 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2025-53782 | Hig | 0.55 | 8.4 | 0.00 | Oct 14, 2025 | Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2023-36050 | Hig | 0.55 | 8.0 | 0.39 | Nov 14, 2023 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2020-17141 | Hig | 0.55 | 8.4 | 0.07 | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability | ||
| CVE-2023-28310 | Hig | 0.54 | 8.0 | 0.25 | Jun 14, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2026-69380 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-55007 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2026 | Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-47631 | Hig | 0.53 | 8.1 | 0.00 | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-45503 | Hig | 0.53 | 8.1 | 0.00 | Jun 9, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53786 | Hig | 0.53 | 8.0 | 0.08 | Aug 6, 2025 | On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation,… | ||
| CVE-2023-35388 | Hig | 0.53 | 8.0 | 0.07 | Aug 8, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2022-21978 | Hig | 0.53 | 8.2 | 0.01 | May 10, 2022 | Microsoft Exchange Server Elevation of Privilege Vulnerability | ||
| CVE-2020-0692 | Hig | 0.53 | 8.1 | 0.03 | Feb 11, 2020 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. | ||
| CVE-2019-1136 | Hig | 0.53 | 8.1 | 0.03 | Jul 15, 2019 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. | ||
| CVE-2017-11932 | Hig | 0.53 | 8.1 | 0.06 | Dec 12, 2017 | Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka "Microsoft Exchange Spoofing Vulnerability". | ||
| CVE-2017-11937 | Hig | 0.53 | 7.8 | 0.28 | Dec 7, 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and… | ||
| CVE-2026-62911 | Hig | 0.52 | 8.0 | 0.01 | Aug 11, 2026 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2023-36439 | Hig | 0.52 | 8.0 | 0.05 | Nov 14, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability |
- risk 0.57cvss 8.8epss 0.02
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.57cvss 8.6epss 0.11
Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.
- risk 0.56cvss 8.5epss 0.04
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.55cvss 8.4epss 0.00
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
- risk 0.55cvss 8.0epss 0.39
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.55cvss 8.4epss 0.07
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.54cvss 8.0epss 0.25
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.01
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 8.1epss 0.00
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
- risk 0.53cvss 8.0epss 0.08
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation,…
- risk 0.53cvss 8.0epss 0.07
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.53cvss 8.2epss 0.01
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.03
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
- risk 0.53cvss 8.1epss 0.03
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
- risk 0.53cvss 8.1epss 0.06
Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka "Microsoft Exchange Spoofing Vulnerability".
- risk 0.53cvss 7.8epss 0.28
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and…
- risk 0.52cvss 8.0epss 0.01
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.52cvss 8.0epss 0.05
Microsoft Exchange Server Remote Code Execution Vulnerability
Page 4 of 13