Microsoft has disclosed multiple elevation of privilege vulnerabilities affecting Microsoft Exchange Server, including CVE-2021-34470, CVE-2021-41348, CVE-2022-41123, and CVE-2025-64666, indicating a recurring security issue in the on-premises mail platform across several release cycles. The advisories show Exchange continued to receive fixes for privilege-escalation weaknesses over multiple years, with Microsoft publishing separate Security Update Guide entries as new flaws were identified.
Among the listed issues, Microsoft provided the most detail for CVE-2021-34470, rating it Important with a CVSS 3.0 score of 8.0 and describing it as requiring access from a logically adjacent network. Microsoft said the flaw required a schema change and was fixed for Exchange Server 2019 and Exchange Server 2016 in cumulative updates released on June 29, 2021; at initial publication, the company said it was not publicly disclosed, not exploited, and less likely to be exploited. A separate Microsoft advisory in the same reference set, CVE-2026-26128, affects the Windows SMB Server rather than Exchange and also involves elevation of privilege.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2026-26128, identified as a Windows SMB Server elevation of privilege vulnerability. No additional synopsis details were provided in the reference.
Microsoft published a Security Update Guide entry for CVE-2025-64666, identified as a Microsoft Exchange Server elevation of privilege vulnerability. No additional synopsis details were provided in the reference.
Microsoft published a Security Update Guide entry for CVE-2022-41123, identified as a Microsoft Exchange Server elevation of privilege vulnerability. No additional synopsis details were provided in the reference.
Microsoft published a Security Update Guide entry for CVE-2021-41348, identified as a Microsoft Exchange Server elevation of privilege vulnerability. No additional synopsis details were provided in the reference.
Microsoft published advisory details for CVE-2021-34470, an Important Microsoft Exchange Server elevation of privilege vulnerability with a CVSS 3.0 score of 8.0. At disclosure, Microsoft assessed it as not publicly disclosed, not exploited, and less likely to be exploited.
Microsoft fixed the Microsoft Exchange Server elevation of privilege vulnerability CVE-2021-34470 in cumulative updates for Exchange Server 2019 and Exchange Server 2016. The fix required a schema change and was released as part of the June 29, 2021 cumulative updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.