Known Vulnerabilities for Exchange Server by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Exchange Server" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-102824 json | Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-102281 json | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with... | Not Provided | 2026-09-28 | 2026-09-29 |
| CVE-2026-101062 json | Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic ... | Not Provided | 2026-09-27 | 2026-09-30 |
| CVE-2026-96940 json | Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. | Not Provided | 2026-10-02 | 2026-10-03 |
| CVE-2026-90452 json | Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange ... | Not Provided | 2026-09-11 | 2026-10-02 |
| CVE-2026-89422 json | Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connec... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-86219 json | Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce ... | Not Provided | 2026-09-06 | 2026-09-08 |
| CVE-2026-81036 json | Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuratio... | Not Provided | 2026-08-26 | 2026-08-29 |
| CVE-2026-77386 json | Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could in... | Not Provided | 2026-09-18 | 2026-09-22 |
| CVE-2026-73430 json | Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by ... | Not Provided | 2026-08-12 | 2026-08-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.5 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 5.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 4.0 | |||
| Application | Microsoft | Exchange Server | 2019 | |||
| Application | Microsoft | Exchange Server | 2019 | |||
| Application | Microsoft | Exchange Server | 2019 |