Patch tracker / Products / Microsoft Exchange Server 2016

Microsoft Exchange Server 2016: vulnerabilities and security updates

Every CVE affecting Microsoft Exchange Server 2016 and the Microsoft update (KB) that fixes it, ranked by real-world risk. Actively exploited (CISA KEV) first, then EPSS exploit probability, on top of CVSS severity.

CVEs
21
Updates (KBs)
25
Actively exploited (KEV)
1
Critical Severity
11

CVEs affecting Microsoft Exchange Server 2016

CVESeverityCVSSEPSSStatus
CVE-2026-42897High8.870%KEV
CVE-2026-45500Critical9.670%-
CVE-2026-45501Critical9.670%-
CVE-2026-45502Critical9.670%-
CVE-2026-45503Critical9.670%-
CVE-2026-45504Critical9.670%-
CVE-2026-45583Critical9.670%-
CVE-2026-47631Critical9.670%-
CVE-2026-55005Critical9.620%-
CVE-2026-55006Critical9.620%-
CVE-2026-55008Critical9.620%-
CVE-2026-55009Critical9.620%-
CVE-2025-53786High8.07.4%-
CVE-2024-49040High7.57.8%-
CVE-2026-21527Medium6.57.7%-
CVE-2025-33051High7.51.3%-
CVE-2025-25005High7.51.3%-
CVE-2025-25006High7.51.3%-
CVE-2025-25007High7.51.3%-
CVE-2025-64667High7.51.0%-
CVE-2025-64666High7.51.0%-

Updates (KBs) for Microsoft Exchange Server 2016

UpdateReleasedSeverityCVSSEPSSCVEsStatus
KB50941392026-06-09High8.870%8KEV
KB50941402026-06-09High8.870%8KEV
KB50941422026-06-09High8.870%8KEV
KB50941442026-06-09High8.870%8KEV
KB51032122026-07-14Critical9.620%11-
KB51032132026-07-14Critical9.620%11-
KB51032142026-07-14Critical9.620%11-
KB51032152026-07-14Critical9.620%11-
KB50471552025-08-12High8.07.4%1-
KB50506722025-08-12High8.07.4%1-
KB50506732025-08-12High8.07.4%1-
KB50506742025-08-12High8.07.4%1-
KB50492332024-11-12High7.57.8%1-
KB50749922026-02-10Medium6.57.7%1-
KB50749932026-02-10Medium6.57.7%1-
KB50749942026-02-10Medium6.57.7%1-
KB50749952026-02-10Medium6.57.7%1-
KB50632212025-08-12High7.51.3%4-
KB50632222025-08-12High7.51.3%4-
KB50632232025-08-12High7.51.3%4-
KB50632242025-08-12High7.51.3%4-
KB50718732025-12-09High7.51.0%2-
KB50718742025-12-09High7.51.0%2-
KB50718752025-12-09High7.51.0%2-
KB50718762025-12-09High7.51.0%2-

Ranked across all products on the Microsoft patch tracker and the CVE and vulnerability management reference. Browse every product: product index.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Data notice: this page, the feeds, and the API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative vendor advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.