Known Vulnerabilities for Exchange Server by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Exchange Server" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41213 json | @node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-i... | Not Provided | 2026-04-23 | 2026-04-25 |
| CVE-2026-34160 json | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notific... | Not Provided | 2026-04-14 | 2026-04-15 |
| CVE-2026-33516 json | xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP capabil... | Not Provided | 2026-04-17 | 2026-04-20 |
| CVE-2026-33371 json | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the... | Not Provided | 2026-03-20 | 2026-03-23 |
| CVE-2026-3497 json | Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patc... | Not Provided | 2026-03-12 | 2026-04-16 |
| CVE-2026-2673 json | Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchang... | Not Provided | 2026-03-13 | 2026-05-12 |
| CVE-2023-38185 json | Microsoft Exchange Server Remote Code Execution Vulnerability | 8.8 - HIGH | 2023-08-08 | 2023-08-10 |
| CVE-2023-38182 json | Microsoft Exchange Server Remote Code Execution Vulnerability | 8 - HIGH | 2023-08-08 | 2023-08-11 |
| CVE-2023-38181 json | Microsoft Exchange Server Spoofing Vulnerability | 8.8 - HIGH | 2023-08-08 | 2023-08-11 |
| CVE-2023-36778 json | Microsoft Exchange Server Remote Code Execution Vulnerability | 8 - HIGH | 2023-10-10 | 2023-10-12 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 2019 | |||
| Application | Microsoft | Exchange Server | 2019 | |||
| Application | Microsoft | Exchange Server | 2019 |