Microsoft Exchange Server 2019
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Exchange Server 2019.
By the Year
In 2026 there have been 1 vulnerability in Microsoft Exchange Server 2019 with an average score of 6.5 out of ten. Last year, in 2025 Exchange Server 2019 had 10 security vulnerabilities published. Right now, Exchange Server 2019 is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 0.51
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 6.50 |
| 2025 | 10 | 7.01 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 5 | 0.00 |
It may take a day or so for new Exchange Server 2019 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Exchange Server 2019 Security Vulnerabilities
Feb 2026: Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-21527
6.5 - Medium
- February 10, 2026
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
User Interface (UI) Misrepresentation of Critical Information
Dec 2025: Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-64666
7.5 - High
- December 09, 2025
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Improper Input Validation
Dec 2025: Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-64667
5.3 - Medium
- December 09, 2025
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
User Interface (UI) Misrepresentation of Critical Information
Oct 2025: Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-59248
7.5 - High
- October 14, 2025
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Improper Input Validation
Oct 2025: Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-59249
8.8 - High
- October 14, 2025
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
1390
Oct 2025: Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-53782
8.4 - High
- October 14, 2025
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
Incorrect Implementation of Authentication Algorithm
Aug 2025: Microsoft Exchange Server Tampering Vulnerability
CVE-2025-25005
6.5 - Medium
- August 12, 2025
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
Improper Input Validation
Aug 2025: Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-25006
5.3 - Medium
- August 12, 2025
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Improper Handling of Additional Special Element
Aug 2025: Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-25007
5.3 - Medium
- August 12, 2025
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Improper Validation of Syntactic Correctness of Input
Aug 2025: Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2025-33051
7.5 - High
- August 12, 2025
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
Information Disclosure
Aug 2025: Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability
CVE-2025-53786
8 - High
- August 06, 2025
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment.
authentification
Nov 2019:
CVE-2019-1373
- November 12, 2019
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.
Sep 2019:
CVE-2019-1233
- September 11, 2019
A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Denial of Service Vulnerability'.
Sep 2019:
CVE-2019-1266
- September 11, 2019
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'.
Jul 2019:
CVE-2019-1084
- July 15, 2019
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
Jul 2019:
CVE-2019-1137
- July 15, 2019
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Exchange Server 2019 or by Microsoft? Click the Watch button to subscribe.