CVE-2026-45502PoC(microsoft / exchange_server)

MEDIUMCVSS 5.0 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft exchange_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_server
  • exchange_server_subscription_edition

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-24); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
exchange_serverexchange_server_subscription_edition

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-23: 1Mentions · 2026-06-24: 2Mentions · 2026-07-01: 1PoC Mentioned / Linked · 2026-06-23: 1PoC Mentioned / Linked · 2026-06-24: 1PoC Mentioned / Linked · 2026-07-01: 1Exploit Tool / Code · 2026-06-23: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 2Technical Details · 2026-07-01: 106-2306-2407-01
Signal classification2 categories
PoC
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-231
PoC1
2026-06-242
General1PoC1
2026-07-011
PoC1
Full discourse4 posts
  • Aretiq.AI@AretiqAI
    PoC

    New Research: CVE-2026-45502 — Microsoft Exchange Server SSRF Any mailbox user can force Exchange to make HTTP requests to internal networks. The SSRF protection only runs on cloud deployments — on-premises servers skip the check entirely. Root cause: the intranet address validation is gated on `isBposUser`, which is always `false` for on-prem Exchange. One SOAP request to EWS InstallApp with a crafted ManifestUrl = blind SSRF from the Exchange server's network position. Affects Exchange 2016 CU23, 2019 CU14/CU15, and Exchange SE. Patched in the June 2026 SU. Full analysis + PoC: https://aretiq.ai/research/15/

    Post summary

    New research discloses an SSRF flaw in on‑premise Microsoft Exchange, provides a PoC via a SOAP request, and notes it is patched in the June 2026 servicing update.

    118187509.3K
    226 followersView on X
  • Aretiq.AI@AretiqAI
    General

    @RossMichaels328 CVE-2026-45502 cannot be chained with PrivExchange/ntlmrelayx for domain compromise. The SSRF is useful for internal network reconnaissance and accessing internal HTTP services, but it does NOT leak Exchange's machine account credentials.

    Post summary

    The post comments on the limitations of CVE‑2026‑45502, noting it is an SSRF that cannot be chained for domain compromise and does not expose machine account credentials.

    10110396
    191 followersView on X
  • iototsecnews@iototsecnews
    PoC

    Microsoft Exchange の SSRF 脆弱性 CVE-2026-45502:PoC の公開と悪用リスク https://iototsecnews.jp/2026/06/24/poc-released-for-microsoft-exchange-server-ews-installapp-ssrf-vulnerability/ この脆弱性 CVE-2026-45502 は、アドインのインストール時にユーザーが指定する URL 検証の不備に起因します。オンプレミス環境において、内部アドレスをブロックするための確認フラグが正しく機能しないため、サーバが任意の URL を信頼してしまいます。その結果として、サーバがネットワークプロキシのように動作し、本来アクセスできない内部のサービスやリソースへの接続に至ります。認証されたユーザーからのリクエストがきっかけとなるため、内部のネットワークが探索されるリスクがあります。ご利用のチームは、ご注意ください。 #CVE202645502 #Microsoft #MicrosoftExchange #PoC #Vulnerability

    Post summary

    A Proof of Concept for the Microsoft Exchange SSRF vulnerability CVE‑2026‑45502 has been publicly released, with technical details outlining how the flaw allows servers to proxy internal requests, though no active exploitation or patch is mentioned.

    01000174
    501 followersView on X
  • Cyber Edition@CyberEdition
    PoC

    ⚠️ A PoC exploit is now public for Microsoft Exchange flaw CVE-2026-45502. Attackers with valid credentials can abuse the SSRF bug to probe internal networks and access sensitive services. If you're running on-prem Exchange, patch now. #CyberSecurity #MicrosoftExchange Read more: https://thecyberedition.com/poc-exploit-released-for-microsoft-exchange-ssrf-vulnerability-patch-now/

    Post summary

    The post announces a public Proof of Concept exploit for Microsoft Exchange CVE-2026-45502 (an SSRF flaw) and urges users to apply the available patch immediately.

    0000099
    739 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server_subscription_edition---

Explore more