CVE-2026-55005
- EPSS 0.66%
- Veröffentlicht 14.07.2026 17:04:57
- Zuletzt bearbeitet 24.07.2026 19:19:21
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-47631
- EPSS 0.35%
- Veröffentlicht 09.06.2026 17:17:35
- Zuletzt bearbeitet 28.07.2026 23:17:04
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-45503
- EPSS 0.45%
- Veröffentlicht 09.06.2026 17:17:26
- Zuletzt bearbeitet 28.07.2026 23:16:58
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
CVE-2026-45583
- EPSS 0.48%
- Veröffentlicht 09.06.2026 17:17:26
- Zuletzt bearbeitet 28.07.2026 23:16:59
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
CVE-2026-45504
- EPSS 0.85%
- Veröffentlicht 09.06.2026 17:17:26
- Zuletzt bearbeitet 28.07.2026 23:16:59
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- EPSS 20.26%
- Veröffentlicht 09.06.2026 17:17:26
- Zuletzt bearbeitet 28.07.2026 23:16:58
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
CVE-2026-45501
- EPSS 0.31%
- Veröffentlicht 09.06.2026 17:17:25
- Zuletzt bearbeitet 28.07.2026 23:16:58
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-45500
- EPSS 0.38%
- Veröffentlicht 09.06.2026 17:17:25
- Zuletzt bearbeitet 28.07.2026 23:16:58
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-42897
- EPSS 70.31%
- Veröffentlicht 14.05.2026 17:00:36
- Zuletzt bearbeitet 15.06.2026 19:19:52
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-21527
- EPSS 7.68%
- Veröffentlicht 10.02.2026 18:16:35
- Zuletzt bearbeitet 15.06.2026 19:15:15
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.