CVE-2026-45502
largeAuthenticated SSRF Information Disclosure in Microsoft Exchange Server
Microsoft Exchange Server is affected by a server-side request forgery (SSRF, CWE-918) that an authorized attacker — an account with only low privileges — can trigger over the network without user interaction. By coercing the Exchange server into issuing requests to attacker-chosen destinations, the attacker can disclose confidential information from the server's internal network context. On-premises deployments of Exchange Server and Exchange Server Subscription Edition are affected; the affected version ranges are not specified in the available data. There is currently no known public proof-of-concept and the flaw is not in CISA's KEV, but its EPSS of 20.3% (97th percentile) signals a substantial probability of exploitation within the next 30 days.
What to do: Monitor the Microsoft Security Response Center advisory for CVE-2026-45502 and apply the Exchange security update for Exchange Server and Exchange Server Subscription Edition as soon as Microsoft publishes it, as specific affected/fixed version numbers are not yet in the available data. Until patched, limit which authenticated users can reach Exchange's client-access services (e.g., OWA/EWS) and restrict the Exchange server's ability to initiate outbound or lateral network requests to sensitive internal endpoints. Since exploitation requires low-privilege credentials, review exposed Exchange endpoints, enforce MFA/conditional access where possible, and watch for unusual outbound connections from Exchange servers.
| Microsoft Exchange Server | — |
| Microsoft Exchange Server Subscription Edition | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
- Vendors
- microsoft
- Products
- exchange server, exchange server subscription edition
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.