Exchange Server Subscription Edition

Vendor:

First CVE: Aug 6, 2025 · Active for under a year

23
Total CVEs
More Total CVEs than 95% of tracked products
11.5
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
4.3%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Exchange Server Subscription Edition over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2025
11 months ago
Most Recent CVE
Jul 14, 2026
12 days ago

CVE Severity & Scoring

Exchange Server Subscription Edition23 CVEs
All CVEs352,719 CVEs
MediumHighCritical
Attack Vector
Local3 (13.0%)
Network20 (87.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (87.0%)
High3 (13.0%)
Unknown0 (0.0%)
User Interaction
None19 (82.6%)
Unknown0 (0.0%)
Required4 (17.4%)
Privileges Required
Low11 (47.8%)
High1 (4.3%)
None11 (47.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network
May 14, 20268.181YESNO
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Jun 9, 20268.842NONO
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network
Jul 14, 20269.639NONO
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
Jun 9, 20265.037NONO
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general i
Aug 6, 20258.035NONO
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Jul 14, 20267.833NONO
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Jul 14, 20268.833NONO
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Jul 14, 20267.832NONO
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network
Jun 9, 20268.130NONO
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
Jun 9, 20268.130NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
1 CVE
4.3% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Exchange Server Subscription Edition

Top CWEs

Versions

No cataloged versions.