CVE-2025-58107

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.

Published 2026-03-02. Last modified 2026-06-17.