Skip to main content
← All Articles

Tag

#Microsoft Exchange Server

8 articles

Advertisement

CVE-2026-96940: Exchange Server Auth Flaw Exposes Mailboxes
HIGH
Vulnerabilities

CVE-2026-96940: Exchange Server Auth Flaw Exposes Mailboxes

Microsoft addresses a high-severity flaw, CVE-2026-96940, in on-premises Exchange Server allowing authenticated attackers to read mailboxes.

Runtime Rebel Intel
3 min read · Oct 6, 2026
HIGH
Vulnerabilities

CVE-2026-62911: Exchange Servers Vulnerable to Mailbox Hijack

Nearly 22,000 Microsoft Exchange Servers remain unpatched against CVE-2026-62911, an auth bypass allowing mailbox hijack attacks.

Runtime Rebel Intel
4 min read · Sep 1, 2026
INFO
Threat Intel

OWA Light Retirement in Exchange Server: Planning for the Change

Microsoft is retiring OWA Light in Exchange Server. This advisory details the operational impact, affected versions, and critical steps for administrators to manage user…

Runtime Rebel Intel
4 min read · Jul 9, 2026
CRITICAL
Vulnerabilities

CVE-2026-42897: Microsoft Exchange XSS Under Active Exploitation

CISA adds CVE-2026-42897, a Microsoft Exchange Server Cross-Site Scripting vulnerability, to KEV Catalog due to active exploitation. Immediate patching advised.

Runtime Rebel Intel
4 min read · May 15, 2026
CRITICAL
Vulnerabilities

CVE-2026-42897: Microsoft Exchange Server Zero-Day Exploited in Wild

Microsoft warns of CVE-2026-42897, a critical Exchange Server zero-day exploited in the wild. Implement Extended Protection mitigations immediately to secure systems.

Runtime Rebel Intel
3 min read · May 15, 2026
CVE-2026-42897: How Attackers Exploit Microsoft Exchange Server
CRITICAL
Vulnerabilities

CVE-2026-42897: How Attackers Exploit Microsoft Exchange Server

Microsoft warns of active exploitation of CVE-2026-42897, a critical spoofing and XSS vulnerability in on-premise Exchange Server triggered via email.

Runtime Rebel Intel
3 min read · May 15, 2026

Advertisement

CRITICAL
Vulnerabilities

Critical RCE Threats: Confluence OGNL & Exchange Server Patching

Runtime Rebel analyzes critical RCE vulnerabilities affecting Atlassian Confluence and Microsoft Exchange Server, alongside a high-severity SQLi in WP Reset.

Runtime Rebel Intel
5 min read · Apr 23, 2026
CRITICAL
Vulnerabilities

CISA KEV Update: Exchange Server, Adobe, MS Windows Exploits

CISA adds seven vulnerabilities, including critical Microsoft Exchange Server deserialization, to its Known Exploited Vulnerabilities Catalog, urging immediate…

Runtime Rebel Intel
4 min read · Apr 14, 2026