| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Exchange products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-65813 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 8.8 | 673 | Neutral | No |
| Yes |
| CVE-2026-65801 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | 10.0 | 720 | Neutral | No | Yes |
| CVE-2026-63359 | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other... | 9.8 | 725 | Neutral | No | No |
| CVE-2026-62915 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | 6.5 | 273 | Neutral | No | Yes |
| CVE-2026-62914 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-62913 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | 8.8 | 545 | Neutral | No | Yes |
| CVE-2026-62912 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. | 6.5 | 338 | Neutral | No | Yes |
| CVE-2026-62911 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 8.0 | 557 | Neutral | Yes | Yes |
| CVE-2026-62910 | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 8.8 | 630 | Neutral | No | Yes |
| CVE-2026-56191 | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | 10.0 | 591 | Neutral | No | Yes |
| CVE-2026-55009 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | 7.8 | 560 | Neutral | No | Yes |
| CVE-2026-55008 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 9.6 | 685 | Neutral | No | Yes |
| CVE-2026-55006 | Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | 7.8 | 431 | Neutral | No | Yes |
| CVE-2026-55005 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | 8.8 | 545 | Neutral | No | Yes |
| CVE-2026-54998 | Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 8.8 | 710 | Neutral | Yes | Yes |
| CVE-2026-48582 | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 9.6 | 644 | Neutral | No | Yes |
| CVE-2026-48579 | Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. | 7.5 | 428 | Neutral | No | Yes |
| CVE-2026-47631 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 5.4 | 228 | Neutral | No | Yes |
| CVE-2026-45583 | Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | 8.1 | 645 | Neutral | No | Yes |
| CVE-2026-45504 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 8.8 | 775 | Neutral | Yes | Yes |