Exchange Server Subscription Edition
by Microsoft
CVEs (27)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-42897 | Hig | 0.70 | 8.1 | 0.70 | KEV | May 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2026-62913 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-45504 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-59249 | Hig | 0.57 | 8.8 | 0.01 | Oct 14, 2025 | Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-53782 | Hig | 0.55 | 8.4 | 0.00 | Oct 14, 2025 | Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-47631 | Hig | 0.53 | 8.1 | 0.00 | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-45503 | Hig | 0.53 | 8.1 | 0.00 | Jun 9, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53786 | Hig | 0.53 | 8.0 | 0.07 | Aug 6, 2025 | On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation,… | ||
| CVE-2026-62911 | Hig | 0.52 | 8.0 | 0.01 | Aug 11, 2026 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-64666 | Hig | 0.49 | 7.5 | 0.01 | Dec 9, 2025 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-59248 | Hig | 0.49 | 7.5 | 0.01 | Oct 14, 2025 | Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-33051 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-62914 | Hig | 0.47 | 7.3 | 0.00 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-62910 | Hig | 0.47 | 7.2 | 0.01 | Aug 11, 2026 | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-21527 | Med | 0.43 | 6.5 | 0.08 | Feb 10, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-62915 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | ||
| CVE-2026-62912 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. | ||
| CVE-2026-45501 | Med | 0.42 | 6.5 | 0.00 | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-25005 | Med | 0.42 | 6.5 | 0.01 | Aug 12, 2025 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | ||
| CVE-2025-64667 | Med | 0.35 | 5.3 | 0.01 | Dec 9, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
- risk 0.70cvss 8.1epss 0.70
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.55cvss 8.4epss 0.00
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
- risk 0.53cvss 8.1epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 8.1epss 0.00
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
- risk 0.53cvss 8.0epss 0.07
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation,…
- risk 0.52cvss 8.0epss 0.01
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.49cvss 7.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
- risk 0.47cvss 7.3epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
- risk 0.47cvss 7.2epss 0.01
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.43cvss 6.5epss 0.08
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.00
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
- risk 0.42cvss 6.5epss 0.01
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
- risk 0.35cvss 5.3epss 0.01
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Page 1 of 2