- EPSS 0.73%
- Veröffentlicht 11.08.2026 17:06:27
- Zuletzt bearbeitet 13.08.2026 18:57:39
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-65813
- EPSS 0.65%
- Veröffentlicht 11.08.2026 17:05:04
- Zuletzt bearbeitet 17.08.2026 12:58:02
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62915
- EPSS 0.48%
- Veröffentlicht 11.08.2026 17:04:45
- Zuletzt bearbeitet 14.08.2026 15:21:48
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-62914
- EPSS 0.53%
- Veröffentlicht 11.08.2026 17:04:45
- Zuletzt bearbeitet 13.08.2026 18:57:33
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-62913
- EPSS 0.62%
- Veröffentlicht 11.08.2026 17:04:44
- Zuletzt bearbeitet 14.08.2026 16:32:17
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-62912
- EPSS 1.31%
- Veröffentlicht 11.08.2026 17:04:44
- Zuletzt bearbeitet 13.08.2026 18:57:36
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
CVE-2026-62910
- EPSS 0.68%
- Veröffentlicht 11.08.2026 17:04:43
- Zuletzt bearbeitet 14.08.2026 15:27:01
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-55009
- EPSS 1.61%
- Veröffentlicht 14.07.2026 17:05:02
- Zuletzt bearbeitet 24.07.2026 19:19:42
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55008
- EPSS 0.85%
- Veröffentlicht 14.07.2026 17:04:58
- Zuletzt bearbeitet 24.07.2026 19:19:30
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-55006
- EPSS 0.21%
- Veröffentlicht 14.07.2026 17:04:58
- Zuletzt bearbeitet 24.07.2026 19:19:25
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.