Junglewise Threat Intelligence

CVE-2026-45502: Microsoft Exchange Server SSRF information disclosure

CVE-2026-45502 · Severity: medium · CVSS 5 · Published 2026-06-09

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server, the widely used corporate email and calendaring platform, is affected by a security vulnerability that could allow an authorized user to access internal information. By exploiting this flaw, an attacker with basic login credentials could force the server to make requests to internal systems that are normally protected. This could lead to the exposure of sensitive internal data or reconnaissance of the private corporate network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Microsoft Exchange Server, classified as CWE-918. The flaw allows an attacker with low-privileged (PR:L) network access to submit requests that the server then executes on their behalf. Because the server often has access to internal resources or metadata services that the user does not, this can be used to bypass network segmentation and disclose sensitive information from the internal environment. The vulnerability has a CVSS score of 5.0, reflecting that while it requires authentication, it can lead to a scope change (S:C) where the server is used as a pivot point. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2026-06-09: advisory: Initial disclosure by Microsoft and NVD

References

Related threats