Junglewise Threat Intelligence

CVE-2026-69361: Microsoft Exchange Server server-side request forgery

CVE-2026-69361 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server is an email and collaboration platform used by organizations worldwide. A server-side request forgery (SSRF) vulnerability allows an authorized attacker to send requests on behalf of the server to internal or external systems, potentially leading to unauthorized access to sensitive data, internal network reconnaissance, or spoofing attacks against connected systems.

Technical details

A server-side request forgery (SSRF) vulnerability exists in Microsoft Exchange Server that permits an authorized attacker to craft malicious requests which the server will execute on their behalf. The vulnerability enables network-accessible request manipulation, allowing an attacker to interact with internal systems, bypass network segmentation, or spoof requests to third-party services. Authentication is required to exploit this vulnerability. The attack vector is network-based and impacts the integrity and confidentiality of systems accessible from the Exchange Server. Patches or security updates are expected from Microsoft.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2026-09-08: disclosed

References

Related threats