CyberMax
Home › Exploited CVEs › Microsoft

Microsoft Exchange Server known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 17 Microsoft Exchange Server CVEs as exploited in the wild. 1 were added in the last 12 months and 13 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 17 Microsoft Exchange Server CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2021-34473Exchange Server Remote Code Execution100.00%Yes2021-11-032021-11-17
2CVE-2021-26855Exchange Server Remote Code Execution100.00%Yes2021-11-032022-05-03
3CVE-2021-34523Exchange Server Privilege Escalation99.99%Yes2021-11-032021-11-17
4CVE-2022-41082Exchange Server Remote Code Execution99.97%Yes2022-09-302022-10-21
5CVE-2020-0688Exchange Server Validation Key Remote Code Execution99.96%Yes2021-11-032022-05-03
6CVE-2022-41040Exchange Server Server-Side Request Forgery99.96%Yes2022-09-302022-10-21
7CVE-2021-27065Exchange Server Remote Code Execution99.88%Yes2021-11-032022-05-03
8CVE-2021-31207Exchange Server Security Feature Bypass99.78%Yes2021-11-032021-11-17
9CVE-2021-33766Exchange Server Information Disclosure98.1%–2022-01-182022-02-01
10CVE-2021-26857Exchange Server Remote Code Execution95.8%Yes2021-11-032022-05-03
11CVE-2021-26858Exchange Server Remote Code Execution93.7%Yes2021-11-032022-05-03
12CVE-2022-41080Exchange Server Privilege Escalation77.3%Yes2023-01-102023-01-31
13CVE-2023-21529Exchange Server Deserialization of Untrusted Data59.3%Yes2026-04-132026-04-27
14CVE-2021-31196Exchange Server Information Disclosure54.1%–2024-08-212024-09-11
15CVE-2020-17144Exchange Server Remote Code Execution36.5%–2021-11-032022-05-03
16CVE-2018-8581Exchange Server Privilege Escalation27.4%Yes2022-03-032022-03-17
17CVE-2024-21410Exchange Server Privilege Escalation12.6%–2024-02-152024-03-07
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Microsoft KEV CVEs · other Microsoft products: SharePoint · Windows · SharePoint Server · Defender · Internet Explorer · Office · Win32k · free KEV badge for Microsoft · all vendors