CVE-2021-33766CISA KEVEPSS p99.9%

CVE-2021-33766Microsoft Exchange Server Information Disclosure

Microsoft / Exchange Server

Description

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.

Scoring

CVSS 7.3 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS98.18% probability of exploitation · percentile 99.9% · 2026-10-05T12:00:23Z
Last modified2026-08-10

CISA KEV entry

Added to KEV: 2022-01-18

(incoming)1

TypeTargetConfidenceTier
KEVEntryMicrosoft Exchange Server Information Disclosurekev-cve-2021-337660%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Microsoft Exchange Server Information Disclosure Vulnerability
CVE
Microsoft Exchange Server Security Feature Bypass Vulnerability
CVE
CVE-2026-48579
CVE
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE
Microsoft Exchange Server Privilege Escalation Vulnerability
CVE
CVE-2026-45503
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.