« Volver al listado

Microsoft

Microsoft Exchange Server Subscription Edition: vulnerabilidades y CVE

Microsoft Exchange Server Subscription Edition tiene 38 vulnerabilidades publicadas, 33 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE38
Últimos 12 meses33
Críticas3
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-42897Media (6.1)0.52%⚠ Explotación activa14 may 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-69641Crítica (9.1)0.86%—8 sept 2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69382Media (5.9)0.47%—8 sept 2026
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
CVE-2026-69380Alta (8.1)0.69%—8 sept 2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69378Alta (7.5)1.2%—8 sept 2026
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
CVE-2026-69375Media (6.5)0.64%—8 sept 2026
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
CVE-2026-69361Media (6.5)0.84%—8 sept 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-69356Crítica (9.3)0.76%—8 sept 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-69355Alta (8.8)0.91%—8 sept 2026
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-65813Alta (8.8)0.94%—11 ago 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62915Media (6.5)0.64%—11 ago 2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-62914Media (5.4)0.45%—11 ago 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-62913Alta (8.8)0.91%—11 ago 2026
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-62912Media (6.5)2.0%—11 ago 2026
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
CVE-2026-62911Alta (8)0.69%—11 ago 2026
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62910Alta (8.8)1.0%—11 ago 2026
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-55009Alta (7.8)2.5%—14 jul 2026
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55008Crítica (9.6)0.86%—14 jul 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-55006Alta (7.8)0.30%—14 jul 2026
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55005Alta (8.8)1.0%—14 jul 2026
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-47631Media (5.4)0.47%—9 jun 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-45583Alta (8.1)0.70%—9 jun 2026
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
CVE-2026-45504Alta (8.8)0.78%—9 jun 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-45503Media (6.5)0.86%—9 jun 2026
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
CVE-2026-45502Media (5)0.64%—9 jun 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
CVE-2026-45501Media (6.1)0.46%—9 jun 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-45500Media (6.1)0.41%—9 jun 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-42897Media (6.1)0.52%⚠ Explotación activa14 may 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-21527Media (6.5)8.1%—10 feb 2026
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-64667Media (5.3)0.80%—9 dic 2025
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-64666Alta (7.5)1.0%—9 dic 2025
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services3
  2. T1078 Valid Accounts2
  3. T1189 Drive-by Compromise2
  4. T1059 Command and Scripting Interpreter1
  5. T1190 Exploit Public-Facing Application1
  6. T1499 Endpoint Denial of Service1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft