Exchange Online Microsoft Exchange Online

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Exchange Online.

Recent Microsoft Exchange Online Security Advisories

Advisory Title Published
CVE-2026-56191 CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability July 23, 2026
CVE-2026-54998 CVE-2026-54998 Microsoft Exchange Online Elevation of Privilege Vulnerability July 2, 2026
CVE-2026-48582 CVE-2026-48582 Microsoft Exchange Online Elevation of Privilege Vulnerability June 18, 2026
CVE-2026-48579 CVE-2026-48579 Microsoft Exchange Online Information Disclosure Vulnerability June 4, 2026

By the Year

In 2026 there have been 5 vulnerabilities in Microsoft Exchange Online with an average score of 9.5 out of ten.

Year Vulnerabilities Average Score
2026 5 9.48

It may take a day or so for new Exchange Online vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Exchange Online Security Vulnerabilities

Jul 2026: Microsoft Exchange Online Tampering Vulnerability
CVE-2026-56191 10 - Critical - July 24, 2026

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

authentification

Jul 2026: Microsoft Exchange Online Elevation of Privilege Vulnerability
CVE-2026-54998 8.8 - High - July 02, 2026

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

AuthZ

Jun 2026: Microsoft Exchange Online Elevation of Privilege Vulnerability
CVE-2026-48582 9.6 - Critical - June 19, 2026

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

AuthZ

Jun 2026: Microsoft Exchange Online Information Disclosure Vulnerability
CVE-2026-48579 9.1 - Critical - June 04, 2026

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

AuthZ

Mar 2026: Microsoft Exchange Elevation of Privilege Vulnerability
CVE-2026-26137 9.9 - Critical - March 19, 2026

Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.

SSRF

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Exchange Online or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe