exchange_server_subscription_edition_rtm vulnerabilities
CVEs whose affected-version data names the exchange_server_subscription_edition_rtm package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
20 CVEsRSS
CVE-2026-69641Critical· 9.1Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69382Medium· 5.9Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
CVE-2026-69380High· 8.1Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69378High· 7.5Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
CVE-2026-69375Medium· 6.5Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
CVE-2026-69361Medium· 6.5Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-69356Critical· 9.3Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-69355High· 8.8External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-55007High· 8.1Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
CVE-2026-62915Medium· 6.5Microsoft Exchange Server Security Feature Bypass Vulnerability
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-62914High· 7.3Microsoft Exchange Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-62913High· 8.8Microsoft Exchange Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-62912Medium· 6.5Microsoft Exchange Server Denial of Service Vulnerability
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
CVE-2026-62910High· 7.2Microsoft Exchange Server Elevation of Privilege Vulnerability
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-65813Medium· 6.5Microsoft Exchange Server Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62911High· 8.0PoCMicrosoft Exchange Server Elevation of Privilege Vulnerability
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-55009High· 7.8Microsoft Exchange Server Elevation of Privilege Vulnerability
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55008Critical· 9.6Microsoft Exchange Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-55006High· 7.8Microsoft Exchange Server Elevation of Privilege Vulnerability
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55005High· 8.8Microsoft Exchange Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.