VendorsMicrosoftexchange_server2016
Vulnerabilities

Microsoft Exchange Server 2016

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

173CVEs
CVE-2023-36778
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
8.0EPSS 0.037
CVE-2022-21980
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
8.0EPSS 0.025
CVE-2022-24516
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
8.0EPSS 0.022
CVE-2022-24477
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
8.0EPSS 0.021
CVE-2023-21762
Microsoft Exchange Server Spoofing Vulnerability
Published 2023-01-10 · Modified
8.0EPSS 0.016
CVE-2023-21745
Microsoft Exchange Server Spoofing Vulnerability
Published 2023-01-10 · Modified
8.0EPSS 0.015
CVE-2021-33768
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2021-07-14 · Modified
8.0EPSS 0.012
CVE-2022-41078
Microsoft Exchange Server Spoofing Vulnerability
Published 2022-11-09 · Modified
8.0EPSS 0.008
CVE-2022-41079
Microsoft Exchange Server Spoofing Vulnerability
Published 2022-11-09 · Modified
8.0EPSS 0.008
CVE-2026-62911
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2026-08-11 · Modified
8.0EPSS 0.007
CVE-2021-41348
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2021-10-13 · Modified
8.0EPSS 0.006
CVE-2021-27065
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Analyzed
7.8KEV1 PoCEPSS 0.999
CVE-2021-26857
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Analyzed
7.8KEVEPSS 0.958
CVE-2021-26858
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Analyzed
7.8KEVEPSS 0.937
CVE-2019-1233
A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Denial of Service Vulnerability'.
Published 2019-09-11 · Modified
7.8EPSS 0.062
CVE-2021-31198
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-05-11 · Modified
7.8EPSS 0.049
CVE-2026-55009
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.025
CVE-2022-41123
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.8EPSS 0.006
CVE-2023-21763
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.006
CVE-2023-21764
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.006
CVE-2026-55006
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.003
CVE-2021-33766
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2021-07-14 · Analyzed
7.5KEVEPSS 0.981
CVE-2024-49040
Microsoft Exchange Server Spoofing Vulnerability
Published 2024-11-12 · Analyzed
7.5EPSS 0.085
CVE-2021-34453
Microsoft Exchange Server Denial of Service Vulnerability
Published 2021-10-13 · Modified
7.5EPSS 0.028
CVE-2023-21761
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2023-01-10 · Modified
7.5EPSS 0.016
CVE-2025-33051
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2025-08-12 · Analyzed
7.5EPSS 0.013
CVE-2025-64666
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2025-12-09 · Analyzed
7.5EPSS 0.010
CVE-2025-59248
Microsoft Exchange Server Spoofing Vulnerability
Published 2025-10-14 · Analyzed
7.5EPSS 0.010
CVE-2018-8581
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
Published 2018-11-14 · Analyzed
7.4KEVEPSS 0.274
CVE-2016-3378
Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "Microsoft Exchange Open Redirect Vulnerability."
Published 2016-09-14 · Modified
7.4EPSS 0.153
CVE-2019-0686
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724.
Published 2019-03-06 · Modified
7.4EPSS 0.050
CVE-2026-62914
Microsoft Exchange Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
7.3EPSS 0.004
CVE-2021-31196
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-07-14 · Analyzed
7.2KEVEPSS 0.541
CVE-2021-26854
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Modified
7.2EPSS 0.247
CVE-2023-21710
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
7.2EPSS 0.079
CVE-2020-16969
Microsoft Exchange Information Disclosure Vulnerability
Published 2020-10-16 · Modified
7.1EPSS 0.027
CVE-2021-31207
Microsoft Exchange Server Security Feature Bypass Vulnerability
Published 2021-05-11 · Analyzed
6.6KEVEPSS 0.998
CVE-2021-41349
Microsoft Exchange Server Spoofing Vulnerability
Published 2021-11-10 · Modified
6.5EPSS 0.935
CVE-2022-24463
Microsoft Exchange Server Spoofing Vulnerability
Published 2022-03-09 · Modified
6.5EPSS 0.318
CVE-2018-0924
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how URL redirects are handled, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0941.
Published 2018-03-14 · Modified
6.5EPSS 0.080
← Prev3 / 5Next →