| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Exchange products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-56191 | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | 10.0 | 591 | Neutral | No |
| Yes |
| CVE-2026-55009 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | 7.8 | 560 | Neutral | No | Yes |
| CVE-2026-55008 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 9.6 | 685 | Neutral | No | Yes |
| CVE-2026-55006 | Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | 7.8 | 431 | Neutral | No | Yes |
| CVE-2026-55005 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | 8.8 | 545 | Neutral | No | Yes |
| CVE-2026-54998 | Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 8.8 | 609 | Neutral | No | Yes |
| CVE-2026-48582 | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 9.6 | 644 | Neutral | No | Yes |
| CVE-2026-48579 | Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. | 7.5 | 428 | Neutral | No | Yes |
| CVE-2026-47631 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 5.4 | 228 | Neutral | No | Yes |
| CVE-2026-45583 | Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | 8.1 | 645 | Neutral | No | Yes |
| CVE-2026-45504 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 8.8 | 775 | Neutral | Yes | Yes |
| CVE-2026-45503 | Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | 6.5 | 338 | Neutral | No | Yes |
| CVE-2026-45502 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | 5.0 | 341 | Neutral | Yes | Yes |
| CVE-2026-45501 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | 6.1 | 293 | Neutral | No | Yes |
| CVE-2026-45500 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 6.1 | 272 | Neutral | No | Yes |
| CVE-2026-42897 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 6.1 | 569 | Neutral | Yes | Yes |
| CVE-2026-4108 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report. | 4.8 | 202 | Neutral | No | Yes |
| CVE-2026-4107 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report. | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-3880 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report. | 4.8 | 202 | Neutral | No | Yes |
| CVE-2026-3879 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report. | 4.8 | 202 | Neutral | No | Yes |