Patch tracker / Products / Microsoft Exchange Server Subscription Edition

Microsoft Exchange Server Subscription Edition: vulnerabilities and security updates

Every CVE affecting Microsoft Exchange Server Subscription Edition and the Microsoft update (KB) that fixes it, ranked by real-world risk. Actively exploited (CISA KEV) first, then EPSS exploit probability, on top of CVSS severity.

CVEs
18
Updates (KBs)
20
Actively exploited (KEV)
0
Critical Severity
11

CVEs affecting Microsoft Exchange Server Subscription Edition

CVESeverityCVSSEPSSStatus
CVE-2026-45500Critical9.670%-
CVE-2026-45501Critical9.670%-
CVE-2026-45502Critical9.670%-
CVE-2026-45503Critical9.670%-
CVE-2026-45504Critical9.670%-
CVE-2026-45583Critical9.670%-
CVE-2026-47631Critical9.670%-
CVE-2026-55005Critical9.620%-
CVE-2026-55006Critical9.620%-
CVE-2026-55008Critical9.620%-
CVE-2026-55009Critical9.620%-
CVE-2025-53786High8.07.4%-
CVE-2025-53782High8.80.9%-
CVE-2025-59249High8.80.9%-
CVE-2025-59248High8.80.9%-
CVE-2026-21527Medium6.57.7%-
CVE-2025-64667High7.51.0%-
CVE-2025-64666High7.51.0%-

Updates (KBs) for Microsoft Exchange Server Subscription Edition

UpdateReleasedSeverityCVSSEPSSCVEsStatus
KB51032122026-07-14Critical9.620%11-
KB51032132026-07-14Critical9.620%11-
KB51032142026-07-14Critical9.620%11-
KB51032152026-07-14Critical9.620%11-
KB50471552025-08-12High8.07.4%1-
KB50506722025-08-12High8.07.4%1-
KB50506732025-08-12High8.07.4%1-
KB50506742025-08-12High8.07.4%1-
KB50663662025-10-14High8.80.9%3-
KB50663672025-10-14High8.80.9%3-
KB50663682025-10-14High8.80.9%3-
KB50663692025-10-14High8.80.9%3-
KB50749922026-02-10Medium6.57.7%1-
KB50749932026-02-10Medium6.57.7%1-
KB50749942026-02-10Medium6.57.7%1-
KB50749952026-02-10Medium6.57.7%1-
KB50718732025-12-09High7.51.0%2-
KB50718742025-12-09High7.51.0%2-
KB50718752025-12-09High7.51.0%2-
KB50718762025-12-09High7.51.0%2-

Ranked across all products on the Microsoft patch tracker and the CVE and vulnerability management reference. Browse every product: product index.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Data notice: this page, the feeds, and the API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative vendor advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.