Microsoft
Microsoft Exchange Server: vulnerabilidades y CVE
Microsoft Exchange Server tiene 255 vulnerabilidades publicadas, 34 de ellas en los últimos 12 meses. 22 son críticas y 20 figuran en el catálogo de explotación activa de CISA.
CVE255
Últimos 12 meses34
Críticas22
Explotadas activamente20
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-42897 | Media (6.1) | 0.52% | ⚠ Explotación activa | 14 may 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2023-21529 | Alta (8.8) | 59% | ⚠ Explotación activa | 14 feb 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-31196 | Alta (7.2) | 54% | ⚠ Explotación activa | 14 jul 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2024-21410 | Crítica (9.8) | 13% | ⚠ Explotación activa | 13 feb 2024 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2022-41080 | Crítica (9.8) | 77% | ⚠ Explotación activa | 9 nov 2022 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2022-41040 | Alta (8.8) | 100% | ⚠ Explotación activa | 3 oct 2022 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2022-41082 | Alta (8) | 100% | ⚠ Explotación activa | 3 oct 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2017-8540 | Alta (7.8) | 72% | ⚠ Explotación activa | 26 may 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,… |
| CVE-2018-8581 | Alta (7.4) | 27% | ⚠ Explotación activa | 14 nov 2018 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. |
| CVE-2021-33766 | Alta (7.5) | 98% | ⚠ Explotación activa | 14 jul 2021 | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2021-42321 | Alta (8.8) | 92% | ⚠ Explotación activa | 10 nov 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-34523 | Crítica (9.8) | 100% | ⚠ Explotación activa | 14 jul 2021 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2020-0688 | Alta (8.8) | 100% | ⚠ Explotación activa | 11 feb 2020 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'. |
| CVE-2020-17144 | Alta (8.8) | 37% | ⚠ Explotación activa | 10 dic 2020 | Microsoft Exchange Remote Code Execution Vulnerability |
| CVE-2021-26858 | Alta (7.8) | 94% | ⚠ Explotación activa | 3 mar 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-27065 | Alta (7.8) | 100% | ⚠ Explotación activa | 3 mar 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26855 | Crítica (9.8) | 100% | ⚠ Explotación activa | 3 mar 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26857 | Alta (7.8) | 96% | ⚠ Explotación activa | 3 mar 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-31207 | Media (6.6) | 100% | ⚠ Explotación activa | 11 may 2021 | Microsoft Exchange Server Security Feature Bypass Vulnerability |
| CVE-2021-34473 | Crítica (9.8) | 100% | ⚠ Explotación activa | 14 jul 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-69641 | Crítica (9.1) | 0.86% | — | 8 sept 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-69382 | Media (5.9) | 0.47% | — | 8 sept 2026 | Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-69380 | Alta (8.1) | 0.69% | — | 8 sept 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-69378 | Alta (7.5) | 1.2% | — | 8 sept 2026 | Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network. |
| CVE-2026-69375 | Media (6.5) | 0.64% | — | 8 sept 2026 | Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. |
| CVE-2026-69361 | Media (6.5) | 0.84% | — | 8 sept 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-69356 | Crítica (9.3) | 0.76% | — | 8 sept 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-69355 | Alta (8.8) | 0.91% | — | 8 sept 2026 | External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. |
| CVE-2026-55007 | Alta (8.1) | 0.72% | — | 8 sept 2026 | Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-65813 | Alta (8.8) | 0.94% | — | 11 ago 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-62915 | Media (6.5) | 0.64% | — | 11 ago 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. |
| CVE-2026-62914 | Media (5.4) | 0.45% | — | 11 ago 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-62913 | Alta (8.8) | 0.91% | — | 11 ago 2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. |
| CVE-2026-62912 | Media (6.5) | 2.0% | — | 11 ago 2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. |
| CVE-2026-62911 | Alta (8) | 0.69% | — | 11 ago 2026 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-62910 | Alta (8.8) | 1.0% | — | 11 ago 2026 | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-55009 | Alta (7.8) | 2.5% | — | 14 jul 2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. |
| CVE-2026-55008 | Crítica (9.6) | 0.86% | — | 14 jul 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-55006 | Alta (7.8) | 0.30% | — | 14 jul 2026 | Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. |
| CVE-2026-55005 | Alta (8.8) | 1.0% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. |
| CVE-2026-47631 | Media (5.4) | 0.47% | — | 9 jun 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-45583 | Alta (8.1) | 0.70% | — | 9 jun 2026 | Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-45504 | Alta (8.8) | 0.78% | — | 9 jun 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-45503 | Media (6.5) | 0.86% | — | 9 jun 2026 | Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-45502 | Media (5) | 0.64% | — | 9 jun 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-45501 | Media (6.1) | 0.46% | — | 9 jun 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-45500 | Media (6.1) | 0.41% | — | 9 jun 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-42897 | Media (6.1) | 0.52% | ⚠ Explotación activa | 14 may 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-21527 | Media (6.5) | 8.1% | — | 10 feb 2026 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-64667 | Media (5.3) | 0.80% | — | 9 dic 2025 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.