Server-side Request Forgery Vulnerability in Microsoft Exchange Server
CVE-2026-45502

5MEDIUM

What is CVE-2026-45502?

A server-side request forgery vulnerability in Microsoft Exchange Server enables an authorized user to disclose sensitive information over a network. This security flaw can be exploited by attackers to manipulate server requests, potentially exposing confidential data. Organizations using affected versions of Microsoft Exchange Server should apply the necessary patches to safeguard their systems and prevent unauthorized data access.

Affected Version(s)

Microsoft Exchange Server 2016 Cumulative Update 23 x64-based Systems 15.01.0.0 < 15.01.2507.069

Microsoft Exchange Server 2019 Cumulative Update 14 x64-based Systems 15.02.0.0 < 15.02.1544.041

Microsoft Exchange Server 2019 Cumulative Update 15 x64-based Systems 15.02.0.0 < 15.02.1748.046

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.