CVE-2026-45504
Microsoft Exchange Server SE vulnerability analysis and mitigation

Overview

CVE-2026-45504 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft Exchange Server that allows an authorized attacker with low-level privileges to elevate their privileges over a network. It affects Microsoft Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Update 14 and 15, and Exchange Server Subscription Edition prior to version 15.02.2562.043. The vulnerability was disclosed and patched on June 9, 2026, as part of Microsoft's June 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 8.8 (High) (MSRC Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where the Exchange Server fails to properly validate or restrict URLs or network requests initiated server-side on behalf of an authenticated user. An attacker with low-privileged network access can craft malicious requests that cause the Exchange Server to make unauthorized internal requests, enabling privilege escalation. No public technical write-up or proof-of-concept code has been identified at this time (MSRC Advisory, Feedly).

Impact

Successful exploitation allows an authorized but low-privileged attacker to escalate privileges on the Exchange Server, potentially gaining unauthorized access to sensitive server resources, internal network services, and confidential email data. The CVSS scoring reflects high impacts to confidentiality, integrity, and availability, meaning a successful attacker could read, modify, or disrupt Exchange Server operations. The SSRF vector also raises the risk of lateral movement to internal systems reachable by the Exchange Server (MSRC Advisory, Feedly).

Mitigation and workarounds

Microsoft released patches for CVE-2026-45504 as part of the June 2026 Patch Tuesday update on June 9, 2026. Administrators should apply the relevant security updates immediately for all affected versions: Exchange Server 2016 CU23 (update to 15.01.2507.069 or later), Exchange Server 2019 CU14 (update to 15.02.1544.041 or later), Exchange Server 2019 CU15 (update to 15.02.1748.046 or later), and Exchange Server Subscription Edition (update to 15.02.2562.043 or later). As a supplementary measure, implement network segmentation to restrict internal server-to-server communication and monitor Exchange Server logs for unusual outbound or internal HTTP requests that may indicate SSRF exploitation attempts (MSRC Advisory, Feedly).

Community reactions

CVE-2026-45504 was covered as part of broader June 2026 Patch Tuesday reporting, which addressed approximately 198–206 vulnerabilities including multiple zero-days, drawing significant industry attention. Security outlets including BleepingComputer, Qualys, Rapid7, Zero Day Initiative, and GBHackers covered the June 2026 Patch Tuesday release, noting the large volume of fixes (BleepingComputer, Qualys Blog, ZDI Blog). This specific CVE did not generate notable standalone commentary, consistent with its lack of public PoC or active exploitation.

Additional resources


SourceThis report was generated using AI

Related Microsoft Exchange Server SE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45504HIGH8.8
  • Microsoft Exchange Server SE logoMicrosoft Exchange Server SE
  • cpe:2.3:a:microsoft:exchange_server:*:*:*:*:subscription:*:*:*
NoYesJun 09, 2026
CVE-2026-21527MEDIUM6.5
  • Microsoft Exchange Server SE logoMicrosoft Exchange Server SE
  • cpe:2.3:a:microsoft:exchange_server:*:*:*:*:subscription:*:*:*
NoYesFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management