CVE-2018-16793: Microsoft Exchange Server
High severity, CVSS 8.6. EPSS: 11.3% chance of exploitation in the next 30 days.
Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.
Affected products
- Microsoft Exchange Server: version 2010 only
Published 2018-09-21. Last modified 2026-06-17.