CVE detail
CVE-2024-26198
Microsoft Exchange Server Remote Code Execution Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
Around 12% of the 45,000 or so Microsoft Exchange servers in Germany that can be accessed from the Internet without restrictions “are so outdated that security updates are no longer offered for them,” the German Federal Office for Information Security (BSI) has warned today. Also, around 25 percent of all those internet-facing servers run Exchange 2016 and 2019, but are not up-to-date with security patches. Urgent action is needed The BSI worries about attackers breaching … More →
newswww.helpnetsecurity.comMar 26, 2024, 1:26 PMOn this March 2024 Patch Tuesday, Microsoft has released fixes for 59 CVE-numbered vulnerabilities, but – welcome news! – none of them are currently publicly known or actively exploited. Last month, though, several days after Patch Tuesday, the company updated two advisories to say that those particular vulnerabilities were being exploited in the wild. One of the two – CVE-2024-21338, an elevation of privilege vulnerability affecting the Windows Kernel – had been reported to Microsoft … More →
newswww.helpnetsecurity.comMar 12, 2024, 7:55 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-36778CVSS 8.0 · High
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-21764CVSS 7.8 · High
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2023-21763CVSS 7.8 · High
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2021-3146CVSS 7.8 · High
The Dolby Audio X2 (DAX2) API service before 0.8.8.90 on Windows allows local users to gain privileges.
- CVE-2026-48395CVSS 8.6 · High
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulne…
- CVE-2026-48391CVSS 8.2 · High
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could expl…