Known Vulnerabilities for Exchange Server by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Exchange Server" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-90452 json | Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange ... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-86219 json | Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce ... | Not Provided | 2026-09-06 | 2026-09-08 |
| CVE-2026-81036 json | Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuratio... | Not Provided | 2026-08-26 | 2026-08-29 |
| CVE-2026-73430 json | Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by ... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-73429 json | Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a ... | Not Provided | 2026-08-12 | 2026-08-14 |
| CVE-2026-69641 json | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-69382 json | Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose inf... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-69380 json | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-69378 json | Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network. | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-69375 json | Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tamper... | Not Provided | 2026-09-08 | 2026-09-11 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 2019 | |||
| Application | Microsoft | Exchange Server | 2019 | |||
| Application | Microsoft | Exchange Server | 2019 |