Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Microsoft Exchange Server 2016 Cumulative Update 23.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-62911HIGH | Microsoft Exchange Server Elevation of Privilege VulnerabilityAuthentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. CWE-294Aug 11, 2026 | CVSS8.0v3.1 | EPSS0.732% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65813MEDIUM | Microsoft Exchange Server Elevation of Privilege VulnerabilityServer-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. CWE-918Aug 11, 2026 | CVSS6.5v3.1 | EPSS0.616% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62915MEDIUM | Microsoft Exchange Server Security Feature Bypass VulnerabilityMissing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. CWE-862Aug 11, 2026 | CVSS6.5v3.1 | EPSS0.494% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62914HIGH | Microsoft Exchange Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. CWE-79Aug 11, 2026 | CVSS7.3v3.1 | EPSS0.532% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62913HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. CWE-122Aug 11, 2026 | CVSS8.8v3.1 | EPSS0.618% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62912MEDIUM | Microsoft Exchange Server Denial of Service VulnerabilityDeserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. CWE-502Aug 11, 2026 | CVSS6.5v3.1 | EPSS1.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62910HIGH | Microsoft Exchange Server Elevation of Privilege VulnerabilityImproper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. CWE-99Aug 11, 2026 | CVSS7.2v3.1 | EPSS0.697% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55009HIGH | Microsoft Exchange Server Elevation of Privilege VulnerabilityDeserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. CWE-502Jul 14, 2026 | CVSS7.8v3.1 | EPSS1.61% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55008CRITICAL | Microsoft Exchange Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. CWE-79Jul 14, 2026 | CVSS9.6v3.1 | EPSS0.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55006HIGH | Microsoft Exchange Server Elevation of Privilege VulnerabilityInsufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. CWE-1220Jul 14, 2026 | CVSS7.8v3.1 | EPSS0.214% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55005HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. CWE-122Jul 14, 2026 | CVSS8.8v3.1 | EPSS0.664% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-47631HIGH | Microsoft Exchange Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. CWE-79Jun 9, 2026 | CVSS8.1v3.1 | EPSS0.353% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45583HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityImproper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. CWE-94Jun 9, 2026 | CVSS7.5v3.1 | EPSS0.475% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45504HIGH | Microsoft Exchange Server Elevation of Privilege VulnerabilityServer-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. CWE-918Jun 9, 2026 | CVSS8.8v3.1 | EPSS0.846% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45503HIGH | Microsoft Exchange Server Information Disclosure VulnerabilityImproper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | CVSS8.1v3.1 | EPSS0.445% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45502MEDIUM | Microsoft Exchange Server Information Disclosure VulnerabilityServer-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. CWE-918Jun 9, 2026 | CVSS5.0v3.1 | EPSS20.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45501MEDIUM | Microsoft Exchange Server Spoofing VulnerabilityServer-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | CVSS6.5v3.1 | EPSS0.308% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-45500MEDIUM | Microsoft Exchange Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. CWE-79Jun 9, 2026 | CVSS6.1v3.1 | EPSS0.375% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42897HIGH | Microsoft Exchange Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. CWE-79May 14, 2026 | CVSS8.1v3.1 | EPSS70.3% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21527MEDIUM | Microsoft Exchange Server Spoofing VulnerabilityUser interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | CVSS6.5v3.1 | EPSS7.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64666HIGH | Microsoft Exchange Server Elevation of Privilege VulnerabilityImproper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. CWE-20Dec 9, 2025 | CVSS7.5v3.1 | EPSS1.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64667MEDIUM | Microsoft Exchange Server Spoofing VulnerabilityUser interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. CWE-451Dec 9, 2025 | CVSS5.3v3.1 | EPSS0.808% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59248HIGH | Microsoft Exchange Server Spoofing VulnerabilityImproper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. CWE-20Oct 14, 2025 | CVSS7.5v3.1 | EPSS0.951% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59249HIGH | Microsoft Exchange Server Elevation of Privilege VulnerabilityWeak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. CWE-1390Oct 14, 2025 | CVSS8.8v3.1 | EPSS0.771% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53782HIGH | Microsoft Exchange Server Elevation of Privilege VulnerabilityIncorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally. CWE-303Oct 14, 2025 | CVSS8.4v3.1 | EPSS0.333% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |