Exchange Server Subscription Edition
Vendor:
First CVE: Aug 6, 2025 · Active for under a year
23
Total CVEs
More Total CVEs than 95% of tracked products
11.5
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
4.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Exchange Server Subscription Edition over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2025
11 months ago
Most Recent CVE
Jul 14, 2026
12 days ago
CVE Severity & Scoring
Exchange Server Subscription Edition23 CVEs
35%
61%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (13.0%)
Network20 (87.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (87.0%)
High3 (13.0%)
Unknown0 (0.0%)
User Interaction
None19 (82.6%)
Unknown0 (0.0%)
Required4 (17.4%)
Privileges Required
Low11 (47.8%)
High1 (4.3%)
None11 (47.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42897HIGH Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network | May 14, 2026 | 8.1 | 81 | YES | NO |
CVE-2026-45504HIGH Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | Jun 9, 2026 | 8.8 | 42 | NO | NO |
CVE-2026-55008CRITICAL Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network | Jul 14, 2026 | 9.6 | 39 | NO | NO |
CVE-2026-45502MEDIUM Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | Jun 9, 2026 | 5.0 | 37 | NO | NO |
CVE-2025-53786HIGH On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general i | Aug 6, 2025 | 8.0 | 35 | NO | NO |
CVE-2026-55009HIGH Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-55005HIGH Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | Jul 14, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-55006HIGH Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | 7.8 | 32 | NO | NO |
CVE-2026-47631HIGH Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network | Jun 9, 2026 | 8.1 | 30 | NO | NO |
CVE-2026-45583HIGH Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 | 8.1 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
1 CVE
4.3% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Exchange Server Subscription Edition
Top CWEs
Versions
No cataloged versions.