Microsoft Exchange Server Subscription Edition Rtm vulnerabilities
23 known vulnerabilities affecting microsoft/microsoft_exchange_server_subscription_edition_rtm.
Total CVEs
23
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH11MEDIUM11
Vulnerabilities
Page 2 of 2
CVE-2026-47631P4MEDIUMCVSS 5.4≥ 15.02.0.0, < 15.02.2562.0432026-06-09
CVE-2026-47631 [MEDIUM] CWE-79 CVE-2026-47631: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-21527MEDIUMCVSS 6.5≥ 15.02.0.0, < 15.02.2562.0372026-02-10
CVE-2026-21527 [MEDIUM] CWE-451 Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
cvelistv5
CVE-2025-64667MEDIUMCVSS 5.3≥ 15.02.0.0, < 15.02.2562.0352025-12-09
CVE-2025-64667 [MEDIUM] CWE-451 Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
cvelistv5
← Previous2 / 2