The current version of Exchange Server is 15.2.2562.49 (as of 08/09/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
9.8 critical · over the network, without login · CISA deadline was 3 May 22
9.8 critical · over the network, without login · CISA deadline was 17 Nov 21
9.8 critical · over the network, without login · CISA deadline was 17 Nov 21
9.8 critical · over the network, without login · CISA deadline was 31 Jan 23
8.8 high · over the network, with a basic account · CISA deadline was 3 May 22
8.8 high · over the network, with a basic account · CISA deadline was 21 Oct 22
8.8 high · over the network, with a basic account · CISA deadline was 27 Apr
8.0 high · from the local network, with a basic account · CISA deadline was 21 Oct 22
7.8 high · locally only, without login, needs user action · CISA deadline was 3 May 22
7.8 high · locally only, without login, needs user action · CISA deadline was 3 May 22
7.8 high · locally only, without login, needs user action · CISA deadline was 3 May 22
7.4 high · over the network, without login · CISA deadline was 17 Mar 22
6.6 medium · over the network, with admin rights only · CISA deadline was 17 Nov 21
- CVE-2024-21410Microsoft Exchange Server Privilege Escalation Vulnerability
9.8 critical · over the network, without login · CISA deadline was 7 Mar 24
- CVE-2020-17144Microsoft Exchange Server Remote Code Execution Vulnerability
8.8 high · over the network, with a basic account · CISA deadline was 3 May 22
- CVE-2021-33766Microsoft Exchange Server Information Disclosure
7.5 high · over the network, without login · CISA deadline was 1 Feb 22
- CVE-2021-31196Microsoft Exchange Server Information Disclosure Vulnerability
7.2 high · over the network, with admin rights only · CISA deadline was 11 Sept 24
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
Exchange Server at a glance
Microsoft Exchange Server (on-premises) is a mail and calendaring platform that has repeatedly been the focus of actively exploited, high-severity vulnerabilities. Microsoft ships cumulative updates plus frequent security updates; here, patch day is planning day — Exchange flaws are weaponized fast and broadly.
For admins timely security updates are non-negotiable, applied in the documented order (schema, then servers), with a health check afterwards. Keep Exchange behind up-to-date TLS, minimize its internet exposure, and consider the Exchange Emergency Mitigation service. Test CUs where possible before production. Track the support lifecycle — older Exchange versions reaching end of support must be migrated or moved to Exchange Online. Subscribe to Microsoft's security bulletins; patchletter flags new builds.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| subscription | 15.2.2562.49 | supported |
| 2019 | 15.2.1544.36 | End of Life |
| 2016 | 15.1.2507.61 | End of Life |
| 2013 | 15.0.1497.48 | End of Life |
| 2010 | 14.3.513.0 | End of Life |
| 2007 | 8.3.517.0 | End of Life |
| 2003 | 6.5.7654.4 | End of Life |
| 2000 | 6.0.6620.7 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 15.2.2562.49 | STABLE | 08/09/2026 | Release notes → |
| 15.2.2562.46 | STABLE | 11/08/2026 | Release notes → |
| 15.2.2562.45 | STABLE | 14/07/2026 | Release notes → |
| 15.2.2562.43 | STABLE | 09/06/2026 | Release notes → |
Frequently asked questions
- What is the latest version of Exchange Server?
- Exchange Server 15.2.2562.49, released 08/09/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Exchange Server release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Exchange Server updates?
- Tick Exchange Server off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new Exchange Server version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current Exchange Server version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/exchange-server)https://patchletter.com/badge/exchange-server.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).