Junglewise Threat Intelligence

CVE-2026-45504: Microsoft Exchange Server privilege escalation via SSRF

CVE-2026-45504 · Severity: high · CVSS 8.8 · Published 2026-06-09

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server, the widely used corporate email and calendaring platform, contains a security vulnerability that could allow an attacker to gain higher levels of access. An individual with basic user credentials on the network could exploit this flaw to impersonate other users or gain administrative control. This could lead to unauthorized access to sensitive corporate communications and potential disruption of email services.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Microsoft Exchange Server, classified as CWE-918. The flaw allows an authenticated attacker with low-level privileges (PR:L) to send specially crafted network requests from the server. By exploiting this, the attacker can bypass security controls to elevate their privileges within the environment. The attack is reachable over the network without user interaction. Microsoft has released information regarding this vulnerability via their Security Update Guide, and administrators should apply the relevant security updates to mitigate the risk of full compromise of confidentiality, integrity, and availability.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Microsoft published the security update guide.

References

Related threats