CVE-2018-16793: Microsoft Exchange Server

High severity, CVSS 8.6. EPSS: 11.3% chance of exploitation in the next 30 days.

Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.

Affected products

Published 2018-09-21. Last modified 2026-06-17.