<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Microsoft Exchange Server</title><description>Cybersecurity articles tagged #Microsoft Exchange Server on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-96940: Exchange Server Auth Flaw Exposes Mailboxes</title><link>https://runtimerebel.com/blog/cve-2026-96940-exchange-server-auth-flaw-exposes-mailboxes</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-96940-exchange-server-auth-flaw-exposes-mailboxes</guid><description>Microsoft addresses a high-severity flaw, CVE-2026-96940, in on-premises Exchange Server allowing authenticated attackers to read mailboxes.</description><pubDate>Tue, 06 Oct 2026 03:50:32 GMT</pubDate><category>CVE-2026-96940</category><category>Microsoft Exchange Server</category><category>Privilege Escalation</category><category>Authorization Bypass</category></item><item><title>CVE-2026-62911: Exchange Servers Vulnerable to Mailbox Hijack</title><link>https://runtimerebel.com/blog/cve-2026-62911-exchange-servers-vulnerable-to-mailbox-hijack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-62911-exchange-servers-vulnerable-to-mailbox-hijack</guid><description>Nearly 22,000 Microsoft Exchange Servers remain unpatched against CVE-2026-62911, an auth bypass allowing mailbox hijack attacks.</description><pubDate>Tue, 01 Sep 2026 12:55:00 GMT</pubDate><category>Microsoft Exchange Server</category><category>Authentication Bypass</category><category>Shadowserver</category><category>CVE-2026-62911</category><category>Mailbox Hijack</category></item><item><title>OWA Light Retirement in Exchange Server: Planning for the Change</title><link>https://runtimerebel.com/blog/owa-light-retirement-in-exchange-server-planning-for-the-change</link><guid isPermaLink="true">https://runtimerebel.com/blog/owa-light-retirement-in-exchange-server-planning-for-the-change</guid><description>Microsoft is retiring OWA Light in Exchange Server. This advisory details the operational impact, affected versions, and critical steps for administrators to manage user…</description><pubDate>Thu, 09 Jul 2026 11:02:25 GMT</pubDate><category>Microsoft Exchange Server</category><category>OWA Light</category><category>Deprecation</category><category>Email Client</category><category>Operational Security</category></item><item><title>CVE-2026-42897: Microsoft Exchange XSS Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-42897-microsoft-exchange-xss-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42897-microsoft-exchange-xss-under-active-exploitation</guid><description>CISA adds CVE-2026-42897, a Microsoft Exchange Server Cross-Site Scripting vulnerability, to KEV Catalog due to active exploitation. Immediate patching advised.</description><pubDate>Fri, 15 May 2026 20:32:11 GMT</pubDate><category>CVE-2026-42897</category><category>Microsoft Exchange Server</category><category>Cross Site Scripting</category><category>XSS</category><category>CISA KEV</category><category>Active Exploitation</category></item><item><title>CVE-2026-42897: Microsoft Exchange Server Zero-Day Exploited in Wild</title><link>https://runtimerebel.com/blog/cve-2026-42897-microsoft-exchange-server-zero-day-exploited-in-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42897-microsoft-exchange-server-zero-day-exploited-in-wild</guid><description>Microsoft warns of CVE-2026-42897, a critical Exchange Server zero-day exploited in the wild. Implement Extended Protection mitigations immediately to secure systems.</description><pubDate>Fri, 15 May 2026 12:47:29 GMT</pubDate><category>CVE-2026-42897</category><category>Microsoft Exchange Server</category><category>Zero-Day</category><category>NTLM Relay</category></item><item><title>CVE-2026-42897: How Attackers Exploit Microsoft Exchange Server</title><link>https://runtimerebel.com/blog/cve-2026-42897-how-attackers-exploit-microsoft-exchange-server</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42897-how-attackers-exploit-microsoft-exchange-server</guid><description>Microsoft warns of active exploitation of CVE-2026-42897, a critical spoofing and XSS vulnerability in on-premise Exchange Server triggered via email.</description><pubDate>Fri, 15 May 2026 09:11:29 GMT</pubDate><category>CVE-2026-42897</category><category>Microsoft Exchange Server</category><category>XSS</category><category>Spoofing</category><category>Zero-Day</category></item><item><title>Critical RCE Threats: Confluence OGNL &amp; Exchange Server Patching</title><link>https://runtimerebel.com/blog/critical-rce-threats-confluence-ognl-exchange-server-patching</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-rce-threats-confluence-ognl-exchange-server-patching</guid><description>Runtime Rebel analyzes critical RCE vulnerabilities affecting Atlassian Confluence and Microsoft Exchange Server, alongside a high-severity SQLi in WP Reset.</description><pubDate>Thu, 23 Apr 2026 05:06:17 GMT</pubDate><category>Atlassian Confluence</category><category>OGNL Injection</category><category>RCE</category><category>Microsoft Exchange Server</category><category>Patch Tuesday</category><category>WordPress</category><category>WP Reset</category><category>SQL Injection</category><category>Vulnerability</category></item><item><title>CISA KEV Update: Exchange Server, Adobe, MS Windows Exploits</title><link>https://runtimerebel.com/blog/cisa-kev-update-exchange-server-adobe-ms-windows-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-exchange-server-adobe-ms-windows-exploits</guid><description>CISA adds seven vulnerabilities, including critical Microsoft Exchange Server deserialization, to its Known Exploited Vulnerabilities Catalog, urging immediate…</description><pubDate>Tue, 14 Apr 2026 00:47:03 GMT</pubDate><category>CVE-2012-1854</category><category>CVE-2020-9715</category><category>CVE-2023-21529</category><category>CVE-2023-36424</category><category>CVE-2025-60710</category><category>CVE-2026-21643</category><category>CVE-2026-34621</category><category>Microsoft Exchange Server</category><category>Adobe Acrobat</category><category>Microsoft Windows</category><category>Fortinet</category><category>CISA</category><category>KEV Catalog</category><category>Deserialization</category><category>Use After Free</category><category>SQL Injection</category></item></channel></rss>