Microsoft Exchange Server

Our sources currently list 247 known vulnerabilities affecting Microsoft Exchange Server. 26 are rated critical severity. 20 of 247 are actively exploited according to CISA, the most recent added 15 May 2026.

Last updated: 22 July 2026, 20:30 AEST

ASD’s ACSC advisory

Russian state-supported cyber actors conduct phishing campaign targeting users of Zimbra Collaboration Suite

Published 2026-07-23 by the Australian Signals Directorate’s Australian Cyber Security Centre

ASD’s ACSC advisory

Russian GRU targeting Western logistics entities and technology companies

Published 2025-05-22 by the Australian Signals Directorate’s Australian Cyber Security Centre

Known vulnerabilities in Microsoft Exchange Server, highest risk first.Showing the 50 highest-risk of 247 total.
CVESeverityExploitationPublishedSummary
CVE-2021-26855Critical (9.1)Actively exploited · ransomwareMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34473Critical (9.1)Actively exploited · ransomwareMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34523Critical (9.0)Actively exploited · ransomwareMicrosoft Exchange Server Elevation of Privilege Vulnerability
CVE-2022-41082High (8.0)Actively exploited · ransomwareMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2020-0688High (8.8)Actively exploited · ransomwareA remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption …
CVE-2021-27065High (7.8)Actively exploited · ransomwareMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2022-41040High (8.8)Actively exploited · ransomwareMicrosoft Exchange Server Elevation of Privilege Vulnerability
CVE-2021-31207Medium (6.6)Actively exploited · ransomwareMicrosoft Exchange Server Security Feature Bypass Vulnerability
CVE-2021-33766High (7.3)Actively exploitedMicrosoft Exchange Server Information Disclosure Vulnerability
CVE-2021-26857High (7.8)Actively exploited · ransomwareMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-42321High (8.8)Actively exploited · ransomwareMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26858High (7.8)Actively exploited · ransomwareMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2022-41080High (8.8)Actively exploited · ransomwareMicrosoft Exchange Server Elevation of Privilege Vulnerability
CVE-2017-8540High (7.8)Actively exploitedThe Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S…
CVE-2023-21529High (8.8)Actively exploited · ransomwareMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-31196High (7.2)Actively exploitedMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2020-17144High (8.4)Actively exploitedMicrosoft Exchange Remote Code Execution Vulnerability
CVE-2018-8581High (7.4)Actively exploited · ransomwareAn elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange S…
CVE-2024-21410Critical (9.8)Actively exploitedMicrosoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-42897High (8.1)Actively exploitedImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network…
CVE-2021-41349Medium (6.5)Elevated likelihood (94%)Microsoft Exchange Server Spoofing Vulnerability
CVE-2020-17132Critical (9.1)Elevated likelihood (90%)Microsoft Exchange Remote Code Execution Vulnerability
CVE-2023-36035High (8.0)Elevated likelihood (87%)Microsoft Exchange Server Spoofing Vulnerability
CVE-2021-28482High (8.8)Elevated likelihood (83%)Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-21707High (8.8)Elevated likelihood (82%)Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-32031High (8.8)Elevated likelihood (82%)Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-36744High (8.0)Elevated likelihood (82%)Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-36777Medium (5.7)Elevated likelihood (81%)Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2023-36745High (8.0)Elevated likelihood (81%)Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2006-0027High (7.5)Elevated likelihood (79%)Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.
CVE-2003-0714High (7.5)Elevated likelihood (76%)The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP servi…
CVE-2023-36756High (8.0)Elevated likelihood (75%)Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-31195Medium (6.5)Elevated likelihood (74%)Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-36039High (8.0)Elevated likelihood (73%)Microsoft Exchange Server Spoofing Vulnerability
CVE-2021-28480Critical (9.8)Elevated likelihood (71%)Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2020-17143High (8.8)Elevated likelihood (71%)Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2005-0560High (7.5)Elevated likelihood (69%)Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary …
CVE-2023-36757High (8.0)Elevated likelihood (69%)Microsoft Exchange Server Spoofing Vulnerability
CVE-2007-0213Critical (10.0)Elevated likelihood (66%)Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a …
CVE-2004-0574Critical (10.0)Elevated likelihood (64%)The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 all…
CVE-2018-0986High (8.8)Elevated likelihood (63%)A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Micros…
CVE-2017-8538High (7.8)Elevated likelihood (50%)The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S…
CVE-2017-8541High (7.8)Elevated likelihood (50%)The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S…
CVE-2020-17117Medium (6.6)Elevated likelihood (49%)Microsoft Exchange Remote Code Execution Vulnerability
CVE-2008-1547Medium (4.3)Elevated likelihood (48%)Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect use…
CVE-2020-16875High (8.4)Elevated likelihood (47%)<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulne…
CVE-2006-0002High (7.5)Elevated likelihood (46%)Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary co…
CVE-2007-0039High (7.8)Elevated likelihood (45%)The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service…
CVE-2005-1987High (7.5)Elevated likelihood (44%)Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CD…
CVE-2022-23277High (8.8)Elevated likelihood (41%)Microsoft Exchange Server Remote Code Execution Vulnerability

Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.

Let's talk

20 of these are being actively exploited right now.

Our Newcastle team can audit your Microsoft estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.