Microsoft Exchange Server Se
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Exchange Server Se.
Recent Microsoft Exchange Server Se Security Advisories
| Advisory | Title | Published |
|---|---|---|
| CVE-2021-31207 | Microsoft Exchange Server Security Feature Bypass Vulnerability | May 11, 2021 |
By the Year
In 2026 there have been 1 vulnerability in Microsoft Exchange Server Se with an average score of 6.5 out of ten. Last year, in 2025 Exchange Server Se had 10 security vulnerabilities published. Right now, Exchange Server Se is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 0.51
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 6.50 |
| 2025 | 10 | 7.01 |
It may take a day or so for new Exchange Server Se vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Exchange Server Se Security Vulnerabilities
Feb 2026: Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-21527
6.5 - Medium
- February 10, 2026
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
User Interface (UI) Misrepresentation of Critical Information
Dec 2025: Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-64666
7.5 - High
- December 09, 2025
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Improper Input Validation
Dec 2025: Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-64667
5.3 - Medium
- December 09, 2025
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
User Interface (UI) Misrepresentation of Critical Information
Oct 2025: Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-59248
7.5 - High
- October 14, 2025
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Improper Input Validation
Oct 2025: Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-59249
8.8 - High
- October 14, 2025
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
1390
Oct 2025: Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-53782
8.4 - High
- October 14, 2025
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
Incorrect Implementation of Authentication Algorithm
Aug 2025: Microsoft Exchange Server Tampering Vulnerability
CVE-2025-25005
6.5 - Medium
- August 12, 2025
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
Improper Input Validation
Aug 2025: Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-25006
5.3 - Medium
- August 12, 2025
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Improper Handling of Additional Special Element
Aug 2025: Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-25007
5.3 - Medium
- August 12, 2025
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Improper Validation of Syntactic Correctness of Input
Aug 2025: Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2025-33051
7.5 - High
- August 12, 2025
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
Information Disclosure
Aug 2025: Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability
CVE-2025-53786
8 - High
- August 06, 2025
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment.
authentification
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Exchange Server Se or by Microsoft? Click the Watch button to subscribe.