ZeroHour

CVE-2026-45502

large

Authenticated SSRF Information Disclosure in Microsoft Exchange Server

CVSS 3.1
5.0 medium
EPSS
20%p97
Published
()
Modified
AI analysis

Microsoft Exchange Server is affected by a server-side request forgery (SSRF, CWE-918) that an authorized attacker — an account with only low privileges — can trigger over the network without user interaction. By coercing the Exchange server into issuing requests to attacker-chosen destinations, the attacker can disclose confidential information from the server's internal network context. On-premises deployments of Exchange Server and Exchange Server Subscription Edition are affected; the affected version ranges are not specified in the available data. There is currently no known public proof-of-concept and the flaw is not in CISA's KEV, but its EPSS of 20.3% (97th percentile) signals a substantial probability of exploitation within the next 30 days.

What to do: Monitor the Microsoft Security Response Center advisory for CVE-2026-45502 and apply the Exchange security update for Exchange Server and Exchange Server Subscription Edition as soon as Microsoft publishes it, as specific affected/fixed version numbers are not yet in the available data. Until patched, limit which authenticated users can reach Exchange's client-access services (e.g., OWA/EWS) and restrict the Exchange server's ability to initiate outbound or lateral network requests to sensitive internal endpoints. Since exploitation requires low-privilege credentials, review exposed Exchange endpoints, enforce MFA/conditional access where possible, and watch for unusual outbound connections from Exchange servers.

Affected
Microsoft Exchange Server
Microsoft Exchange Server Subscription Edition
Estimated exposure
largetens of thousands of internet-exposed Exchange servers; total on-prem Exchange deployments likely in the hundreds of thousands — Internet-wide scans have historically shown tens of thousands of exposed Exchange/OWA endpoints, and the on-prem Exchange installed base across organizations not yet migrated to Microsoft 365 is in the hundreds of thousands, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Vendors
microsoft
Products
exchange server, exchange server subscription edition
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.