product of microsoft

exchange server subscription edition

9 thingsrelated by NVD

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69641
Severity critical
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over…
CVE-2026-69382
Severity medium
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69380
Severity high
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
CVE-2026-69378
Severity high
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a…
CVE-2026-69375
Severity medium
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-69361
Severity medium
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized…
CVE-2026-69356
Severity critical
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-69355
Severity high
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
CVE-2026-55007
Severity high