Product of Microsoft

Exchange Server

As of , 17 Microsoft Exchange Server vulnerabilities are on CISA's list of exploited vulnerabilities, 13 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2023-21529.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2023-21529Deserialization of Untrusted DataMicrosoft Exchange ServerPatch nowRansomware use, listed within a year0.59
2CVE-2020-0688Validation Key Remote Code ExecutionMicrosoft Exchange ServerPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
3CVE-2022-41040Server-Side Request ForgeryMicrosoft Exchange ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
4CVE-2022-41082Remote Code ExecutionMicrosoft Exchange ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
5CVE-2021-26855Remote Code ExecutionMicrosoft Exchange ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
6CVE-2021-27065Remote Code ExecutionMicrosoft Exchange ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
7CVE-2021-31207Security Feature BypassMicrosoft Exchange ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
8CVE-2021-34473Remote Code ExecutionMicrosoft Exchange ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
9CVE-2021-34523Privilege EscalationMicrosoft Exchange ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
10CVE-2022-41080Privilege EscalationMicrosoft Exchange ServerPatch this weekRansomware use; EPSS 0.770.77
11CVE-2021-33766Information DisclosureMicrosoft Exchange ServerPatch this weekEPSS 0.980.98
12CVE-2021-26857Remote Code ExecutionMicrosoft Exchange ServerPatch this weekRansomware use; EPSS 0.960.96
13CVE-2021-26858Remote Code ExecutionMicrosoft Exchange ServerPatch this weekRansomware use; EPSS 0.940.94
14CVE-2021-31196Information DisclosureMicrosoft Exchange ServerPatch this weekEPSS 0.540.54
15CVE-2018-8581Privilege EscalationMicrosoft Exchange ServerPatch this weekRansomware use0.27
16CVE-2020-17144Remote Code ExecutionMicrosoft Exchange ServerPatch soon0.37
17CVE-2024-21410Privilege EscalationMicrosoft Exchange ServerPatch soon0.13

Added each year

5102021: 9920212022: 4420222023: 1120232024: 2220242025: nonenone20252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20219
20224
20231
20242
2025none
20261

Used in ransomware

Changes CISA made to these entries

  1. CVE-2023-21529 Microsoft Exchange ServerRansomware use: Unknown to Known.
  2. CVE-2021-27065 Microsoft Exchange ServerDeadline moved from 16 April 2021 to 3 May 2022.
  3. CVE-2021-26858 Microsoft Exchange ServerDeadline moved from 16 April 2021 to 3 May 2022.
  4. CVE-2021-26857 Microsoft Exchange ServerDeadline moved from 16 April 2021 to 3 May 2022.
  5. CVE-2021-26855 Microsoft Exchange ServerDeadline moved from 16 April 2021 to 3 May 2022.

Every change we recorded