Microsoft’s Security Update Guide lists several vulnerabilities spanning Exchange Server and Windows components, including CVE-2022-41092, CVE-2022-41120, CVE-2024-49009, CVE-2025-21206, and CVE-2025-62570. The references point to official MSRC advisory pages, indicating these issues were tracked through Microsoft’s vulnerability disclosure and patching process even though the provided entries do not include technical synopses.
The set includes older Exchange-related flaws alongside newer Microsoft-tracked CVEs, suggesting continued attention to enterprise software exposure across on-premises messaging and Windows ecosystems. Organizations relying on Microsoft products would need to review the corresponding MSRC pages, determine affected versions, and apply available security updates or mitigations to reduce the risk of exploitation tied to these identifiers.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2023-41763, creating an official advisory record for the vulnerability.
Microsoft published a Security Update Guide entry for CVE-2025-49703, formally creating an official advisory record for the vulnerability.
Microsoft published a Security Update Guide entry for CVE-2025-62570, formally listing the vulnerability in its advisory portal.
Microsoft published a Security Update Guide entry for CVE-2025-21206, creating an official vulnerability record in its update guide.
Microsoft published a Security Update Guide entry for CVE-2024-49009, signaling official tracking and disclosure of the vulnerability.
Microsoft added CVE-2022-41120 to its Security Update Guide, marking disclosure of the vulnerability through an official product advisory entry.
Microsoft added CVE-2022-41092 to its Security Update Guide, indicating public disclosure of the vulnerability and associated advisory information.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.