Known Exploited Vulnerability: CVE-2018-8581

Microsoft Exchange Server Privilege Escalation Vulnerability

Catalog version: 2026.06.29 Date added: 2022-03-03 Due date: 2022-03-17 CISA catalog

Vendor: Microsoft

Product: Exchange Server

Required action: Apply updates per vendor instructions.

Known ransomware campaign use: Known

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8581

cvelogic Threat Intelligence