Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Exchange Server
Total 258 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-62911 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-09-02 N/A 8.0 HIGH
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2021-26858 1 Microsoft 1 Exchange Server 2026-08-19 6.8 MEDIUM 7.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-42321 1 Microsoft 1 Exchange Server 2026-08-19 6.5 MEDIUM 8.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-27065 1 Microsoft 1 Exchange Server 2026-08-19 6.8 MEDIUM 7.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26857 1 Microsoft 1 Exchange Server 2026-08-19 6.8 MEDIUM 7.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26855 1 Microsoft 1 Exchange Server 2026-08-19 7.5 HIGH 9.1 CRITICAL
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-21707 1 Microsoft 1 Exchange Server 2026-08-19 N/A 8.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-21706 1 Microsoft 1 Exchange Server 2026-08-19 N/A 8.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-21529 1 Microsoft 1 Exchange Server 2026-08-19 N/A 8.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-42305 1 Microsoft 1 Exchange Server 2026-08-19 4.3 MEDIUM 6.5 MEDIUM
Microsoft Exchange Server Spoofing Vulnerability
CVE-2021-41349 1 Microsoft 1 Exchange Server 2026-08-19 4.3 MEDIUM 6.5 MEDIUM
Microsoft Exchange Server Spoofing Vulnerability
CVE-2021-27078 1 Microsoft 1 Exchange Server 2026-08-19 6.5 MEDIUM 9.1 CRITICAL
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26854 1 Microsoft 1 Exchange Server 2026-08-19 6.5 MEDIUM 6.6 MEDIUM
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26412 1 Microsoft 1 Exchange Server 2026-08-19 6.5 MEDIUM 9.1 CRITICAL
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2026-65813 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-17 N/A 6.5 MEDIUM
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62913 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-14 N/A 8.8 HIGH
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-62910 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-14 N/A 7.2 HIGH
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62915 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-14 N/A 6.5 MEDIUM
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-62912 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-13 N/A 6.5 MEDIUM
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
CVE-2026-62914 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-13 N/A 7.3 HIGH
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.