Microsoft
Microsoft Exchange Server Subscription Edition: vulnerabilidades y CVE
Microsoft Exchange Server Subscription Edition tiene 38 vulnerabilidades publicadas, 33 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE38
Últimos 12 meses33
Críticas3
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-42897 | Media (6.1) | 0.52% | ⚠ Explotación activa | 14 may 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-69641 | Crítica (9.1) | 0.86% | — | 8 sept 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-69382 | Media (5.9) | 0.47% | — | 8 sept 2026 | Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-69380 | Alta (8.1) | 0.69% | — | 8 sept 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-69378 | Alta (7.5) | 1.2% | — | 8 sept 2026 | Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network. |
| CVE-2026-69375 | Media (6.5) | 0.64% | — | 8 sept 2026 | Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. |
| CVE-2026-69361 | Media (6.5) | 0.84% | — | 8 sept 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-69356 | Crítica (9.3) | 0.76% | — | 8 sept 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-69355 | Alta (8.8) | 0.91% | — | 8 sept 2026 | External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. |
| CVE-2026-65813 | Alta (8.8) | 0.94% | — | 11 ago 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-62915 | Media (6.5) | 0.64% | — | 11 ago 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. |
| CVE-2026-62914 | Media (5.4) | 0.45% | — | 11 ago 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-62913 | Alta (8.8) | 0.91% | — | 11 ago 2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. |
| CVE-2026-62912 | Media (6.5) | 2.0% | — | 11 ago 2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. |
| CVE-2026-62911 | Alta (8) | 0.69% | — | 11 ago 2026 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-62910 | Alta (8.8) | 1.0% | — | 11 ago 2026 | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-55009 | Alta (7.8) | 2.5% | — | 14 jul 2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. |
| CVE-2026-55008 | Crítica (9.6) | 0.86% | — | 14 jul 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-55006 | Alta (7.8) | 0.30% | — | 14 jul 2026 | Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. |
| CVE-2026-55005 | Alta (8.8) | 1.0% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. |
| CVE-2026-47631 | Media (5.4) | 0.47% | — | 9 jun 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-45583 | Alta (8.1) | 0.70% | — | 9 jun 2026 | Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-45504 | Alta (8.8) | 0.78% | — | 9 jun 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-45503 | Media (6.5) | 0.86% | — | 9 jun 2026 | Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-45502 | Media (5) | 0.64% | — | 9 jun 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-45501 | Media (6.1) | 0.46% | — | 9 jun 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-45500 | Media (6.1) | 0.41% | — | 9 jun 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-42897 | Media (6.1) | 0.52% | ⚠ Explotación activa | 14 may 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-21527 | Media (6.5) | 8.1% | — | 10 feb 2026 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-64667 | Media (5.3) | 0.80% | — | 9 dic 2025 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-64666 | Alta (7.5) | 1.0% | — | 9 dic 2025 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.