Microsoft Exchange Server Subscription Edition RTM
Microsoft- Software type
- —
- Catalog vulnerabilities
- 39
Severity across 39 analyzed records
en
Severity across 39 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, within CyStack's analyzed data, Microsoft Exchange Server Subscription Edition RTM has 20 security vulnerabilities published in the last 90 days. Of these, 14 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Microsoft Exchange Server Subscription Edition RTM and determine which vulnerabilities affect that version.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-69641Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation statusNot known exploited | FixYes | Published09/08/2026 | SeverityCritical |
CVE-2026-69382Microsoft Exchange Server Information Disclosure Vulnerability | Exploitation statusNot known exploited | FixYes | Published09/08/2026 | SeverityMedium |
CVE-2026-69380Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation statusNot known exploited | FixYes | Published09/08/2026 | SeverityHigh |
CVE-2026-69378Microsoft Exchange Server Denial of Service Vulnerability | Exploitation statusNot known exploited | FixYes | Published09/08/2026 | SeverityHigh |
CVE-2026-69375Microsoft Exchange Server Tampering Vulnerability | Exploitation statusNot confirmed | FixYes | Published09/08/2026 | SeverityMedium |
CVE-2026-69361Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusNot known exploited | FixYes | Published09/08/2026 | SeverityMedium |
CVE-2026-69356Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusNot known exploited | FixYes | Published09/08/2026 | SeverityCritical |
CVE-2026-69355Microsoft Exchange Server Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixYes | Published09/08/2026 | SeverityHigh |
CVE-2026-55007Microsoft Exchange Server Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixYes | Published09/08/2026 | SeverityHigh |
CVE-2026-62911Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation statusPublic exploit | FixYes | Published08/11/2026 | SeverityHigh |
CVE-2026-65813Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityMedium |
CVE-2026-62915Microsoft Exchange Server Security Feature Bypass Vulnerability | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityMedium |
CVE-2026-62914Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityHigh |
CVE-2026-62913Microsoft Exchange Server Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityHigh |
CVE-2026-62912Microsoft Exchange Server Denial of Service Vulnerability | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityMedium |
CVE-2026-62910Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityHigh |
CVE-2026-55009Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation statusNot known exploited | FixYes | Published07/14/2026 | SeverityHigh |
CVE-2026-55008Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusNot known exploited | FixYes | Published07/14/2026 | SeverityCritical |
CVE-2026-55006Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation statusNot known exploited | FixYes | Published07/14/2026 | SeverityHigh |
CVE-2026-55005Microsoft Exchange Server Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixYes | Published07/14/2026 | SeverityHigh |
CVE-2026-47631Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusNot known exploited | FixYes | Published06/09/2026 | SeverityHigh |
CVE-2026-45583Microsoft Exchange Server Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixYes | Published06/09/2026 | SeverityHigh |
CVE-2026-45504Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation statusNot known exploited | FixYes | Published06/09/2026 | SeverityHigh |
CVE-2026-45503Microsoft Exchange Server Information Disclosure Vulnerability | Exploitation statusNot known exploited | FixYes | Published06/09/2026 | SeverityHigh |
CVE-2026-45502Microsoft Exchange Server Information Disclosure Vulnerability | Exploitation statusNot known exploited | FixYes | Published06/09/2026 | SeverityMedium |
CVE-2026-45501Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusNot known exploited | FixYes | Published06/09/2026 | SeverityMedium |
CVE-2026-45500Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusNot known exploited | FixYes | Published06/09/2026 | SeverityMedium |
CVE-2026-42897Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusKEV | FixYes | Published05/14/2026 | SeverityHigh |
CVE-2026-21527Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusNot known exploited | FixYes | Published02/10/2026 | SeverityMedium |
CVE-2025-64666Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityHigh |
CVE-2025-64667Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityMedium |
CVE-2025-59248Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusNot known exploited | FixYes | Published10/14/2025 | SeverityHigh |
CVE-2025-59249Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation statusNot known exploited | FixYes | Published10/14/2025 | SeverityHigh |
CVE-2025-53782Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation statusNot known exploited | FixYes | Published10/14/2025 | SeverityHigh |
CVE-2025-25007Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusNot known exploited | FixYes | Published08/12/2025 | SeverityMedium |
CVE-2025-25006Microsoft Exchange Server Spoofing Vulnerability | Exploitation statusNot known exploited | FixYes | Published08/12/2025 | SeverityMedium |
CVE-2025-25005Microsoft Exchange Server Tampering Vulnerability | Exploitation statusNot known exploited | FixYes | Published08/12/2025 | SeverityMedium |
CVE-2025-33051Microsoft Exchange Server Information Disclosure Vulnerability | Exploitation statusNot known exploited | FixYes | Published08/12/2025 | SeverityHigh |
CVE-2025-53786Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability | Exploitation statusNot known exploited | FixYes | Published08/06/2025 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan