Exchange Server

Microsoft · current 15.2.2562.46

The current version of Exchange Server is 15.2.2562.46 (as of 11/08/2026). patchletter checks the official source daily and emails you every new release.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.

  • CVE-2021-26855Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 3 May 22

  • CVE-2021-34473Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 17 Nov 21

  • CVE-2021-34523Microsoft Exchange Server Privilege Escalation VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 17 Nov 21

  • CVE-2022-41080Microsoft Exchange Server Privilege Escalation VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 31 Jan 23

  • CVE-2020-0688Microsoft Exchange Server Validation Key Remote Code Execution VulnerabilityRansomware

    8.8 high · over the network, with a basic account · CISA deadline was 3 May 22

  • CVE-2022-41040Microsoft Exchange Server Server-Side Request Forgery VulnerabilityRansomware

    8.8 high · over the network, with a basic account · CISA deadline was 21 Oct 22

  • CVE-2023-21529Microsoft Exchange Server Deserialization of Untrusted Data VulnerabilityRansomware

    8.8 high · over the network, with a basic account · CISA deadline was 27 Apr

  • CVE-2022-41082Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware

    8.0 high · from the local network, with a basic account · CISA deadline was 21 Oct 22

  • CVE-2021-26857Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware

    7.8 high · locally only, without login, needs user action · CISA deadline was 3 May 22

  • CVE-2021-27065Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware

    7.8 high · locally only, without login, needs user action · CISA deadline was 3 May 22

  • CVE-2021-26858Microsoft Exchange Server Remote Code Execution VulnerabilityRansomware

    7.8 high · locally only, without login, needs user action · CISA deadline was 3 May 22

  • CVE-2018-8581Microsoft Exchange Server Privilege Escalation VulnerabilityRansomware

    7.4 high · over the network, without login · CISA deadline was 17 Mar 22

  • CVE-2021-31207Microsoft Exchange Server Security Feature Bypass VulnerabilityRansomware

    6.6 medium · over the network, with admin rights only · CISA deadline was 17 Nov 21

  • CVE-2024-21410Microsoft Exchange Server Privilege Escalation Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 7 Mar 24

  • CVE-2020-17144Microsoft Exchange Server Remote Code Execution Vulnerability

    8.8 high · over the network, with a basic account · CISA deadline was 3 May 22

  • CVE-2021-33766Microsoft Exchange Server Information Disclosure

    7.5 high · over the network, without login · CISA deadline was 1 Feb 22

  • CVE-2021-31196Microsoft Exchange Server Information Disclosure Vulnerability

    7.2 high · over the network, with admin rights only · CISA deadline was 11 Sept 24

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

Exchange Server at a glance

Microsoft Exchange Server (on-premises) is a mail and calendaring platform that has repeatedly been the focus of actively exploited, high-severity vulnerabilities. Microsoft ships cumulative updates plus frequent security updates; here, patch day is planning day — Exchange flaws are weaponized fast and broadly.

For admins timely security updates are non-negotiable, applied in the documented order (schema, then servers), with a health check afterwards. Keep Exchange behind up-to-date TLS, minimize its internet exposure, and consider the Exchange Emergency Mitigation service. Test CUs where possible before production. Track the support lifecycle — older Exchange versions reaching end of support must be migrated or moved to Exchange Online. Subscribe to Microsoft's security bulletins; patchletter flags new builds.

Support cycles (endoflife.date)

CycleLatest versionStatus
subscription15.2.2562.46supported
201915.2.1544.36End of Life
201615.1.2507.61End of Life
201315.0.1497.48End of Life
201014.3.513.0End of Life
20078.3.517.0End of Life
20036.5.7654.4End of Life
20006.0.6620.7End of Life

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
15.2.2562.46STABLE11/08/2026Release notes →
15.2.2562.45STABLE14/07/2026Release notes →
15.2.2562.43STABLE09/06/2026Release notes →

Frequently asked questions

What is the latest version of Exchange Server?
Exchange Server 15.2.2562.46, released 11/08/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the Exchange Server release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new Exchange Server updates?
Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.

Never miss a Exchange Server update

We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.

Watch Exchange Server

Embed this badge

Shows the current Exchange Server version and updates itself. Free to use, no account needed.

Exchange Server badge
[![Exchange Server](https://patchletter.com/badge/exchange-server.svg)](https://patchletter.com/en/software/exchange-server)
https://patchletter.com/badge/exchange-server.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Servers & Databases