Microsoft

Exchange Server Subscription Edition

40 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.8

CVE-2026-96940

Medienbericht
  • EPSS 0.5%
  • Veröffentlicht 02.10.2026 19:06:19
  • Zuletzt bearbeitet 06.10.2026 15:05:34

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Medienbericht
  • EPSS 0.85%
  • Veröffentlicht 08.09.2026 17:12:56
  • Zuletzt bearbeitet 22.09.2026 12:23:27

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Medienbericht
  • EPSS 0.44%
  • Veröffentlicht 08.09.2026 17:12:48
  • Zuletzt bearbeitet 29.09.2026 15:05:31

Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

Medienbericht
  • EPSS 0.71%
  • Veröffentlicht 08.09.2026 17:12:47
  • Zuletzt bearbeitet 29.09.2026 15:17:09

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Medienbericht
  • EPSS 1.11%
  • Veröffentlicht 08.09.2026 17:12:46
  • Zuletzt bearbeitet 29.09.2026 15:54:45

Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.

Medienbericht
  • EPSS 0.59%
  • Veröffentlicht 08.09.2026 17:12:46
  • Zuletzt bearbeitet 29.09.2026 15:55:25

Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

Medienbericht
  • EPSS 0.79%
  • Veröffentlicht 08.09.2026 17:12:45
  • Zuletzt bearbeitet 29.09.2026 20:20:52

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Medienbericht
  • EPSS 0.7%
  • Veröffentlicht 08.09.2026 17:12:45
  • Zuletzt bearbeitet 30.09.2026 12:29:48

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Medienbericht
  • EPSS 0.84%
  • Veröffentlicht 08.09.2026 17:12:44
  • Zuletzt bearbeitet 30.09.2026 12:30:17

External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

Medienbericht
  • EPSS 0.73%
  • Veröffentlicht 08.09.2026 17:10:39
  • Zuletzt bearbeitet 05.10.2026 17:11:46

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.