Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Exchange Server Subscription Edition
Total 30 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-62911 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-09-02 N/A 8.0 HIGH
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-65813 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-17 N/A 6.5 MEDIUM
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62913 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-14 N/A 8.8 HIGH
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-62910 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-14 N/A 7.2 HIGH
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62915 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-14 N/A 6.5 MEDIUM
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-62912 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-13 N/A 6.5 MEDIUM
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
CVE-2026-62914 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-13 N/A 7.3 HIGH
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-47631 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-07-28 N/A 8.1 HIGH
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-45583 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-07-28 N/A 7.5 HIGH
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
CVE-2026-45504 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-07-28 N/A 8.8 HIGH
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-45503 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-07-28 N/A 8.1 HIGH
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
CVE-2026-45502 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-07-28 N/A 5.0 MEDIUM
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
CVE-2026-45501 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-07-28 N/A 6.5 MEDIUM
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-45500 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-07-28 N/A 6.1 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-55009 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-07-24 N/A 7.8 HIGH
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55008 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-07-24 N/A 9.6 CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-55006 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-07-24 N/A 7.8 HIGH
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55005 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-07-24 N/A 8.8 HIGH
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-42897 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-06-17 N/A 8.1 HIGH
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-21527 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-06-17 N/A 6.5 MEDIUM
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.