All CVEs
Vulnerability intelligence

CVE-2020-0688

Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

Microsoft Exchange Server

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

CVSS Score
8.8
High
EPSS — Exploit Probability
100%
Riskier than 100% of all CVEs · checked 2026-09-21
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
unknown
Federal deadline 2022-05-03
CISA required action

Apply updates per vendor instructions. Deadline for federal agencies: 2022-05-03.

NVD entry PoC / advisory CISA KEV

1 article across 1 outlet · first covered Sep 21, 2026 · latest Sep 21, 2026

Associated threat actors

Coverage timeline

Related CVEs — Microsoft