Junglewise Threat Intelligence

CVE-2026-45503: Microsoft Exchange Server SSRF in Server Component

CVE-2026-45503 · Severity: high · CVSS 8.1 · Published 2026-06-09

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server, the widely used corporate email and calendaring platform, is affected by a security vulnerability that could allow an authorized user to access sensitive information. By exploiting this flaw, an attacker with basic login credentials could force the server to make unauthorized requests to internal or external systems. This could lead to the exposure of private data or unauthorized access to other services within the corporate network.

Technical details

A server-side request forgery (SSRF) vulnerability exists in Microsoft Exchange Server due to improper authorization (CWE-285). An authenticated attacker with low-level privileges can exploit this flaw over the network without any user interaction. By sending specially crafted requests, the attacker can force the Exchange server to perform web requests to arbitrary destinations, potentially bypassing firewalls or accessing internal metadata services. This can result in high-impact information disclosure and unauthorized data modification. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2026-06-09: advisory: Initial disclosure by Microsoft and NVD
  • 2026-06-09: patched: Security updates made available via Microsoft Update Guide

References

Related threats