VulnSea

exchange_server_2019_cumulative_update_14 vulnerabilities

CVEs whose affected-version data names the exchange_server_2019_cumulative_update_14 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

20 CVEsRSS

CVE-2026-69641Critical· 9.1
1w ago

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.85%via NVD
CVE-2026-69382Medium· 5.9
1w ago

Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.44%via NVD
CVE-2026-69380High· 8.1
1w ago

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.71%via NVD
CVE-2026-69378High· 7.5
1w ago

Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.

Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 1.1%via NVD
CVE-2026-69375Medium· 6.5
1w ago

Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

SunlitMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.59%via NVD
CVE-2026-69361Medium· 6.5
1w ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

SunlitMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.79%via NVD
CVE-2026-69356Critical· 9.3
1w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

MidnightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.70%via NVD
CVE-2026-69355High· 8.8
1w ago

External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.84%via NVD
CVE-2026-55007High· 8.1
1w ago

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

TwilightMicrosoft · Microsoft Exchange Server 2019 Cumulative Update 14EPSS 0.73%via NVD
CVE-2026-62915Medium· 6.5
1mo ago

Microsoft Exchange Server Security Feature Bypass Vulnerability

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

SunlitMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.48%via CVEORG
CVE-2026-62914High· 7.3
1mo ago

Microsoft Exchange Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.34%via CVEORG
CVE-2026-62913High· 8.8
1mo ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.65%via CVEORG
CVE-2026-62912Medium· 6.5
1mo ago

Microsoft Exchange Server Denial of Service Vulnerability

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.

SunlitMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 1.3%via CVEORG
CVE-2026-62910High· 7.2
1mo ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.68%via CVEORG
CVE-2026-65813Medium· 6.5
1mo ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

SunlitMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.65%via CVEORG
CVE-2026-62911High· 8.0PoC
1mo ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 1.3%via CVEORG
CVE-2026-55009High· 7.8
2mo ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 2.5%via CVEORG
CVE-2026-55008Critical· 9.6
2mo ago

Microsoft Exchange Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

MidnightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.86%via CVEORG
CVE-2026-55006High· 7.8
2mo ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.30%via CVEORG
CVE-2026-55005High· 8.8
2mo ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 1.0%via CVEORG
exchange_server_2019_cumulative_update_14 vulnerabilities (CVEs) · VulnSea