Known Vulnerabilities for Exchange Server by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Exchange Server" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73430 json | Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by ... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-73429 json | Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a ... | Not Provided | 2026-08-12 | 2026-08-14 |
| CVE-2026-66907 json | Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-66906 json | Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from ... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-65813 json | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a ne... | Not Provided | 2026-08-11 | 2026-08-16 |
| CVE-2026-65801 json | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a ... | Not Provided | 2026-08-20 | 2026-08-24 |
| CVE-2026-63621 json | Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-62915 json | Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | Not Provided | 2026-08-11 | 2026-08-13 |
| CVE-2026-62914 json | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an a... | Not Provided | 2026-08-11 | 2026-08-13 |
| CVE-2026-62913 json | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | Not Provided | 2026-08-11 | 2026-08-14 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 2019 | |||
| Application | Microsoft | Exchange Server | 2019 | |||
| Application | Microsoft | Exchange Server | 2019 |