VendorsMicrosoftexchange_server2016
Vulnerabilities

Microsoft Exchange Server 2016

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

173CVEs
CVE-2017-8542
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE-2017-8535, CVE-2017-8536, CVE-2017-8537, and CVE-2017-8539.
Published 2017-05-26 · Modified
5.5EPSS 0.060
CVE-2020-0903
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.
Published 2020-03-12 · Modified
5.4EPSS 0.016
CVE-2019-1137
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.
Published 2019-07-29 · Modified
5.4EPSS 0.016
CVE-2017-11761
Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability"
Published 2017-09-13 · Modified
5.3EPSS 0.066
CVE-2022-34692
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2022-08-09 · Modified
5.3EPSS 0.017
CVE-2025-25006
Microsoft Exchange Server Spoofing Vulnerability
Published 2025-08-12 · Analyzed
5.3EPSS 0.009
CVE-2025-25007
Microsoft Exchange Server Spoofing Vulnerability
Published 2025-08-12 · Analyzed
5.3EPSS 0.009
CVE-2025-64667
Microsoft Exchange Server Spoofing Vulnerability
Published 2025-12-09 · Analyzed
5.3EPSS 0.008
CVE-2026-45502
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2026-06-09 · Analyzed
5.0EPSS 0.006
CVE-2016-0138
Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Outlook application information by leveraging the Send As right, aka "Microsoft Exchange Information Disclosure Vulnerability."
Published 2016-09-14 · Modified
4.3EPSS 0.135
CVE-2018-8151
An information disclosure vulnerability exists when Microsoft Exchange improperly handles objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8154.
Published 2018-05-09 · Modified
4.3EPSS 0.089
CVE-2018-8374
A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server.
Published 2018-08-15 · Modified
4.3EPSS 0.030
CVE-2018-8604
A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server.
Published 2018-12-12 · Modified
4.3EPSS 0.024
← Prev5 / 5