← KEV catalog
CISA known exploited vulnerability

CVE-2021-33766

Microsoft Exchange Server Information Disclosure

SOURCE FACT

Microsoft · Exchange Server

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2021-33766

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?