AI description
CVE-2026-45504 is identified as a Server-Side Request Forgery (SSRF) vulnerability affecting Microsoft Exchange Server. This flaw, categorized under CWE-918, enables an authenticated attacker to elevate privileges across a network. The vulnerability resides in Exchange Server's request-handling logic, which processes attacker-controlled URLs without adequate validation, allowing the server to initiate requests to internal resources on behalf of the attacker. Exploitation of CVE-2026-45504 can allow an authenticated user with low privileges to submit crafted requests, causing the Exchange server to make outbound or internal HTTP calls. These requests inherit the trust of the Exchange service account, potentially granting the attacker access to resources that would otherwise be inaccessible from their session. In some instances, this SSRF can be leveraged to read arbitrary local files from the Exchange server. This vulnerability was disclosed as part of Microsoft's June 2026 Patch Tuesday release.
- Description
- Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- exchange_server, exchange_server_subscription_edition
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-918
- Hype score
- Not currently trending
CVE-2026-45504. 0day Intel: 🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-45504 PT ID: PT-
@lyrie_ai
16 Jul 2026
88 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
hawktrace/CVE-2026-45504: CVE-2026-45504 Microsoft Exchange File Read · GitHub https://t.co/bG5PJs9ngi
@willyc0de
24 Jun 2026
2552 Impressions
9 Retweets
42 Likes
23 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:*",
"matchCriteriaId": "FF76AEDA-E574-40ED-B64F-8FDEF8CAC802",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_14:*:*:*:*:*:*",
"matchCriteriaId": "8C98993B-82A5-48CC-947F-896CEA0CDB7F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_15:*:*:*:*:*:*",
"matchCriteriaId": "7166BCE0-1D55-46B2-96B9-250AB4BB6291",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server_subscription_edition:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A4DB559B-001D-487D-8EA2-36F8AD7BAF51",
"versionEndExcluding": "15.02.2562.043",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]