Exchange Server 2016 Microsoft Exchange Server 2016

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Exchange Server 2016.

By the Year

In 2026 there have been 1 vulnerability in Microsoft Exchange Server 2016 with an average score of 6.5 out of ten. Last year, in 2025 Exchange Server 2016 had 10 security vulnerabilities published. Right now, Exchange Server 2016 is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 0.51

Year Vulnerabilities Average Score
2026 1 6.50
2025 10 7.01
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 6 0.00

It may take a day or so for new Exchange Server 2016 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Exchange Server 2016 Security Vulnerabilities

Feb 2026: Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-21527 6.5 - Medium - February 10, 2026

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

User Interface (UI) Misrepresentation of Critical Information

Dec 2025: Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-64666 7.5 - High - December 09, 2025

Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Improper Input Validation

Dec 2025: Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-64667 5.3 - Medium - December 09, 2025

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

User Interface (UI) Misrepresentation of Critical Information

Oct 2025: Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-59248 7.5 - High - October 14, 2025

Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Improper Input Validation

Oct 2025: Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-59249 8.8 - High - October 14, 2025

Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

1390

Oct 2025: Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-53782 8.4 - High - October 14, 2025

Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

Incorrect Implementation of Authentication Algorithm

Aug 2025: Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-25006 5.3 - Medium - August 12, 2025

Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Improper Handling of Additional Special Element

Aug 2025: Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2025-33051 7.5 - High - August 12, 2025

Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

Information Disclosure

Aug 2025: Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-25007 5.3 - Medium - August 12, 2025

Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Improper Validation of Syntactic Correctness of Input

Aug 2025: Microsoft Exchange Server Tampering Vulnerability
CVE-2025-25005 6.5 - Medium - August 12, 2025

Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

Improper Input Validation

Aug 2025: Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability
CVE-2025-53786 8 - High - August 06, 2025

On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment.

authentification

Nov 2019:
CVE-2019-1373 - November 12, 2019

A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.

Sep 2019:
CVE-2019-1233 - September 11, 2019

A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Denial of Service Vulnerability'.

Sep 2019:
CVE-2019-1266 - September 11, 2019

A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'.

Jul 2019:
CVE-2019-1084 - July 15, 2019

An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.

Jul 2019:
CVE-2019-1136 - July 15, 2019

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.

Jul 2019:
CVE-2019-1137 - July 15, 2019

A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Exchange Server 2016 or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe