
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-45504 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft Exchange Server that allows an authorized attacker with low-level privileges to elevate their privileges over a network. It affects Microsoft Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Update 14 and 15, and Exchange Server Subscription Edition prior to version 15.02.2562.043. The vulnerability was disclosed and patched on June 9, 2026, as part of Microsoft's June 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 8.8 (High) (MSRC Advisory, Feedly).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where the Exchange Server fails to properly validate or restrict URLs or network requests initiated server-side on behalf of an authenticated user. An attacker with low-privileged network access can craft malicious requests that cause the Exchange Server to make unauthorized internal requests, enabling privilege escalation. No public technical write-up or proof-of-concept code has been identified at this time (MSRC Advisory, Feedly).
Successful exploitation allows an authorized but low-privileged attacker to escalate privileges on the Exchange Server, potentially gaining unauthorized access to sensitive server resources, internal network services, and confidential email data. The CVSS scoring reflects high impacts to confidentiality, integrity, and availability, meaning a successful attacker could read, modify, or disrupt Exchange Server operations. The SSRF vector also raises the risk of lateral movement to internal systems reachable by the Exchange Server (MSRC Advisory, Feedly).
Microsoft released patches for CVE-2026-45504 as part of the June 2026 Patch Tuesday update on June 9, 2026. Administrators should apply the relevant security updates immediately for all affected versions: Exchange Server 2016 CU23 (update to 15.01.2507.069 or later), Exchange Server 2019 CU14 (update to 15.02.1544.041 or later), Exchange Server 2019 CU15 (update to 15.02.1748.046 or later), and Exchange Server Subscription Edition (update to 15.02.2562.043 or later). As a supplementary measure, implement network segmentation to restrict internal server-to-server communication and monitor Exchange Server logs for unusual outbound or internal HTTP requests that may indicate SSRF exploitation attempts (MSRC Advisory, Feedly).
CVE-2026-45504 was covered as part of broader June 2026 Patch Tuesday reporting, which addressed approximately 198–206 vulnerabilities including multiple zero-days, drawing significant industry attention. Security outlets including BleepingComputer, Qualys, Rapid7, Zero Day Initiative, and GBHackers covered the June 2026 Patch Tuesday release, noting the large volume of fixes (BleepingComputer, Qualys Blog, ZDI Blog). This specific CVE did not generate notable standalone commentary, consistent with its lack of public PoC or active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."