Known Vulnerabilities for Exchange Online by Microsoft
Listed below are 5 of the newest known vulnerabilities associated with "Exchange Online" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65801 json | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a ... | Not Provided | 2026-08-20 | 2026-08-24 |
| CVE-2026-56191 json | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | Not Provided | 2026-07-24 | 2026-07-28 |
| CVE-2026-54998 json | Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | Not Provided | 2026-07-02 | 2026-07-07 |
| CVE-2026-48582 json | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | Not Provided | 2026-06-19 | 2026-06-24 |
| CVE-2026-48579 json | Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. | Not Provided | 2026-06-04 | 2026-07-15 |
| CVE-2026-16053 json | Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Trave... | Not Provided | 2026-08-11 | 2026-08-11 |