« Volver al listado

Microsoft

Microsoft Exchange Server: vulnerabilidades y CVE

Microsoft Exchange Server tiene 255 vulnerabilidades publicadas, 34 de ellas en los últimos 12 meses. 22 son críticas y 20 figuran en el catálogo de explotación activa de CISA.

CVE255
Últimos 12 meses34
Críticas22
Explotadas activamente20

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-42897Media (6.1)0.52%⚠ Explotación activa14 may 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2023-21529Alta (8.8)59%⚠ Explotación activa14 feb 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-31196Alta (7.2)54%⚠ Explotación activa14 jul 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2024-21410Crítica (9.8)13%⚠ Explotación activa13 feb 2024
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2022-41080Crítica (9.8)77%⚠ Explotación activa9 nov 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2022-41040Alta (8.8)100%⚠ Explotación activa3 oct 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2022-41082Alta (8)100%⚠ Explotación activa3 oct 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2017-8540Alta (7.8)72%⚠ Explotación activa26 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,…
CVE-2018-8581Alta (7.4)27%⚠ Explotación activa14 nov 2018
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
CVE-2021-33766Alta (7.5)98%⚠ Explotación activa14 jul 2021
Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2021-42321Alta (8.8)92%⚠ Explotación activa10 nov 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34523Crítica (9.8)100%⚠ Explotación activa14 jul 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2020-0688Alta (8.8)100%⚠ Explotación activa11 feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
CVE-2020-17144Alta (8.8)37%⚠ Explotación activa10 dic 2020
Microsoft Exchange Remote Code Execution Vulnerability
CVE-2021-26858Alta (7.8)94%⚠ Explotación activa3 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-27065Alta (7.8)100%⚠ Explotación activa3 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26855Crítica (9.8)100%⚠ Explotación activa3 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26857Alta (7.8)96%⚠ Explotación activa3 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-31207Media (6.6)100%⚠ Explotación activa11 may 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
CVE-2021-34473Crítica (9.8)100%⚠ Explotación activa14 jul 2021
Microsoft Exchange Server Remote Code Execution Vulnerability

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-69641Crítica (9.1)0.86%—8 sept 2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69382Media (5.9)0.47%—8 sept 2026
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
CVE-2026-69380Alta (8.1)0.69%—8 sept 2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69378Alta (7.5)1.2%—8 sept 2026
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
CVE-2026-69375Media (6.5)0.64%—8 sept 2026
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
CVE-2026-69361Media (6.5)0.84%—8 sept 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-69356Crítica (9.3)0.76%—8 sept 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-69355Alta (8.8)0.91%—8 sept 2026
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-55007Alta (8.1)0.72%—8 sept 2026
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
CVE-2026-65813Alta (8.8)0.94%—11 ago 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62915Media (6.5)0.64%—11 ago 2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-62914Media (5.4)0.45%—11 ago 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-62913Alta (8.8)0.91%—11 ago 2026
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-62912Media (6.5)2.0%—11 ago 2026
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
CVE-2026-62911Alta (8)0.69%—11 ago 2026
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62910Alta (8.8)1.0%—11 ago 2026
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-55009Alta (7.8)2.5%—14 jul 2026
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55008Crítica (9.6)0.86%—14 jul 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-55006Alta (7.8)0.30%—14 jul 2026
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55005Alta (8.8)1.0%—14 jul 2026
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-47631Media (5.4)0.47%—9 jun 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-45583Alta (8.1)0.70%—9 jun 2026
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
CVE-2026-45504Alta (8.8)0.78%—9 jun 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-45503Media (6.5)0.86%—9 jun 2026
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
CVE-2026-45502Media (5)0.64%—9 jun 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
CVE-2026-45501Media (6.1)0.46%—9 jun 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-45500Media (6.1)0.41%—9 jun 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-42897Media (6.1)0.52%⚠ Explotación activa14 may 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-21527Media (6.5)8.1%—10 feb 2026
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-64667Media (5.3)0.80%—9 dic 2025
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.001 PowerShell9
  2. T1210 Exploitation of Remote Services8
  3. T1190 Exploit Public-Facing Application7
  4. T1059 Command and Scripting Interpreter5
  5. T1068 Exploitation for Privilege Escalation4
  6. T1005 Data from Local System1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft