CVE-2026-45504PoC(microsoft / exchange_server)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch microsoft exchange_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_server
  • exchange_server_subscription_edition

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 29 mentions across 12 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 20 signals
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 20 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 10d ago at 9 mentions (2026-06-24); latest day: 3
  • 29 total mentions across 12 days

Affected systems

Vendors
Products
exchange_serverexchange_server_subscription_edition

2 versions affected across 2 products

Deep dive

Activity timeline29 mentions / 12d
02579Mentions · 2026-06-23: 1Mentions · 2026-06-24: 9Mentions · 2026-06-25: 1Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Mentions · 2026-06-29: 1Mentions · 2026-07-03: 4Mentions · 2026-07-04: 4Mentions · 2026-07-05: 2Mentions · 2026-07-06: 1Mentions · 2026-07-10: 1Mentions · 2026-07-16: 3PoC Mentioned / Linked · 2026-06-24: 6PoC Mentioned / Linked · 2026-06-25: 1PoC Mentioned / Linked · 2026-06-27: 1PoC Mentioned / Linked · 2026-06-29: 1PoC Mentioned / Linked · 2026-07-03: 3PoC Mentioned / Linked · 2026-07-04: 2PoC Mentioned / Linked · 2026-07-05: 2PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-10: 1PoC Mentioned / Linked · 2026-07-16: 2Exploit Tool / Code · 2026-06-24: 4Exploit Tool / Code · 2026-06-25: 1Exploit Tool / Code · 2026-07-03: 2Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-07-03: 4Patch / Workaround · 2026-07-04: 2Technical Details · 2026-06-24: 6Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 1Technical Details · 2026-07-03: 4Technical Details · 2026-07-04: 4Technical Details · 2026-07-05: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-16: 106-2306-2406-2506-2606-2706-2907-0307-0407-0507-0607-1007-16
Signal classification5 categories
PoC
1862.1%
Disclosure
620.7%
General
26.9%
Patch
26.9%
Disclosis
13.4%
Referenced assets20 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-231
Disclosure1
2026-06-249
Disclosure1General1Patch1PoC6
2026-06-251
PoC1
2026-06-261
Disclosure1
2026-06-271
PoC1
2026-06-291
Disclosis1
2026-07-034
Disclosure1Patch1PoC2
2026-07-044
Disclosure2PoC2
2026-07-052
PoC2
2026-07-061
PoC1
2026-07-101
PoC1
2026-07-163
General1PoC2
Full discourse20 posts
  • HawkTrace@hawktrace
    Disclosure

    🚨 Microsoft Exchange - CVE-2026-45504🚨 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45504 https://t.co/zk9xUfDVTw

    Post summary

    The tweet briefly alerts to Microsoft Exchange CVE‑2026‑45504 and directs readers to the MSRC update guide, without providing technical details, exploitation info, or patch guidance.

    048121714243.7K
    558 followersView on X
  • HawkTrace@hawktrace
    Disclosure

    Our technical write-up on CVE-2026-45504 is now live. https://hawktrace.com/blog/CVE-2026-45504/ #exchange #cve-2026-45504 #hawktrace

    Post summary

    An announcement that a technical write‑up for CVE‑2026‑45504 is now available, but no further details or actionable information are disclosed.

    04721387935.2K
    558 followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    🚨 CVE-2026-45504: Microsoft Exchange File Read CVSS: 8.8 PoC Published: June 24th, 2026 PoC: https://github.com/hawktrace/CVE-2026-45504 Writeup: https://hawktrace.com/blog/CVE-2026-45504/ https://t.co/yfU90q10u3

    Post summary

    Proof‑of‑concept code and writeup for CVE‑2026‑45504 have been published; no active exploitation or patch has been reported.

    22411044015.8K
    226.8K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🚨 Microsoft Exchange'teki CVE-2026-45504 numaralı SSRF açığının nasıl istismar edildiğini gösteren araştırmacı HawkTrace'e ait bir POC. Msrc kaydı: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45504 https://t.co/7sdUj2KEXL

    Post summary

    The post announces a Proof of Concept for the newly disclosed Microsoft Exchange SSRF vulnerability CVE-2026-45504, with a link to the official Msrc advisory.

    210087528.1K
    1.7K followersView on X
  • willy.P@willyc0de
    PoC

    hawktrace/CVE-2026-45504: CVE-2026-45504 Microsoft Exchange File Read · GitHub https://github.com/hawktrace/CVE-2026-45504

    Post summary

    The GitHub repository linked provides a proof‑of‑concept for CVE-2026-45504, a Microsoft Exchange file‑read vulnerability, with no evidence of active exploitation or patch availability.

    012067324.3K
    300 followersView on X
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-45504 PT ID: PT-2026-47976 Vendor: Microsoft Product: Microsoft Exchange Server 2016 Cumulative Update 23 Description: Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Link: https://github.com/hawktrace/CVE-2026-45504 #dbugs_vuln

    Post summary

    A PoC and exploit script for CVE‑2026‑45504, a server‑side request forgery in Microsoft Exchange Server 2016 that can elevate privileges, has been released, but no active exploitation or patch information is provided.

    015057293.7K
    3.0K followersView on X
  • elhacker.NET@elhackernet
    PoC

    Publican exploit PoC para vulnerabilidad de escalada de privilegios en Microsoft Exchange Server Se ha publicado una prueba de concepto (PoC) para la vulnerabilidad CVE-2026-45504, un fallo de falsificación de solicitudes del lado del servidor (SSRF) de severidad alta en Microsoft Exchange Server https://blog.elhacker.net/2026/06/publican-exploit-poc-para.html

    Post summary

    El post informa que se ha publicado una prueba de concepto para la vulnerabilidad SSRF CVE-2026-45504 en Microsoft Exchange Server, sin detalle de código funcional ni indicios de explotación activa.

    01003264.3K
    141.3K followersView on X
  • dbugs@ptdbugs
    Disclosure

    📌 Analysis of the CVE-2026-45504 vulnerability in Microsoft Exchange that allows reading arbitrary files PT ID: PT-2026-47976 The article examines the CVE-2026-45504 vulnerability, which affects Microsoft Exchange Server. Researchers demonstrated that even a low-privileged user can gain access to arbitrary files on the server via an SSRF chain by exploiting improper URL scheme validation. The attack is based on manipulating the "WebApplicationUrl" and using the “#” fragment, which allows bypassing appended parameters and forcing the server to read local files. As a result, an attacker can extract sensitive data. 📎 Article: https://hawktrace.com/blog/CVE-2026-45504/ #dbugs_attacks

    Post summary

    The post provides technical details on CVE-2026-45504, explaining how malformed URLs and SSRF can lead to arbitrary file reads in Microsoft Exchange, but it does not discuss active exploitation, PoC, or available fixes.

    06024101.2K
    3.0K followersView on X
  • blackorbird@blackorbird
    PoC

    Any low-privileged user on Microsoft Exchange can read arbitrary files from the system without authorization. https://hawktrace.com/blog/CVE-2026-45504/ https://github.com/hawktrace/CVE-2026-45504/blob/main/CVE-2026-45504.py https://t.co/7jJBIoTuuG

    Post summary

    A blog post and GitHub script reveal a PoC for CVE‑2026‑45504 that allows low‑privileged users to read arbitrary files on Microsoft Exchange; no patch or exploitation notice is provided.

    07021103.0K
    43.3K followersView on X
  • 🕳@sekurlsa_pw
    PoC

    PoC is linked in article Or if you directly want to check it https://github.com/hawktrace/CVE-2026-45504

    Post summary

    A Proof of Concept for CVE‑2026‑45504 has been shared via a GitHub repository, with no mention of active exploitation or patches.

    01012123.0K
    2.7K followersView on X
  • SoyITPro@SoyITPro
    Patch

    Actualizaciones disponibles para corregir vulnerabilidad de elevación de privilegios en #ExchangeServer en todas sus versiones. 🚨 CVE-2026-45504 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45504

    Post summary

    Microsoft has released updates to patch CVE‑2026‑45504, a privilege‑escalation vulnerability that affects all Exchange Server versions.

    0001421.4K
    13.2K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    PoC

    HawkTrace publicly disclosed Microsoft Exchange vulnerability CVE-2026-45504 with PoC exploit code. The SSRF flaw reads arbitrary files. Patch now. #MicrosoftExchange #CVE202645504 #SSRF #Cybersecurity #PoC #Infosec http://securityonline.info/microsoft-exchange-cve-2026-45504/

    Post summary

    HawkTrace publicly disclosed CVE-2026-45504, sharing PoC exploit code for an SSRF flaw that permits arbitrary file reads, and a patch has been released.

    00032748
    12.9K followersView on X
  • batuu@int20z
    General

    @ridvanyagli Paylaşım için teşekkürler teknik blog yazıma göz atın https://hawktrace.com/blog/CVE-2026-45504/

    Post summary

    The user shares a link to a blog post on CVE‑2026‑45504 with no further details, PoC, exploit tools, patches, or evidence of active exploitation.

    00041203
    338 followersView on X
  • キタきつね@foxbook
    PoC

    Microsoft Exchangeの脆弱性CVE-2026-45504に対する概念実証(PoC)エクスプロイトが公開される Microsoft Exchange Vulnerability CVE-2026-45504 Gets Public PoC Exploit #DailyCyberSecurity (Jul 3) https://securityonline.info/microsoft-exchange-cve-2026-45504/

    Post summary

    A public proof‑of‑concept exploit for Microsoft Exchange CVE‑2026‑45504 has been released, but no exploitation code, patches, or claims of active attacks are detailed.

    00031411
    5.0K followersView on X
  • Cyber Edition@CyberEdition
    Disclosure

    🛡️ A newly disclosed flaw in Microsoft Exchange Server 2019 (CVE-2026-45504) lets any authenticated user read arbitrary server files via an SSRF vulnerability. Admins should review WOPI/EWS settings and patch as soon as available. #CyberSecurity #Microsoft Read more: https://thecyberedition.com/microsoft-exchange-ssrf-bug-lets-users-read-server-files/

    Post summary

    A newly disclosed Microsoft Exchange flaw (CVE-2026-45504) lets authenticated users read arbitrary server files via an SSRF vulnerability, and admins are urged to review settings and apply patches promptly.

    00020100
    739 followersView on X
  • CCB Alert@CCBalert
    Disclosis

    Warning: New #PrivEsc vulnerability #CVE-2026-45504 affecting Microsoft #Exchange Server 2016, 2019 and SE has been disclosed along with a #PoC. Protect your Microsoft environments, migrate to Exchange Server SE if you haven't already and #Patch https://ccb.belgium.be/advisories/warning-privilege-escalation-vulnerability-exchange-server-2016-2019-and-subscription

    Post summary

    CVE-2026-45504, a privilege‑ escalation flaw in Microsoft Exchange Server 2016/2019/SE, has been publicly disclosed with an accompanying PoC, and users are warned to patch or migrate to the Subscription Edition.

    01001432
    7.2K followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Vendor. 0day Intel: 🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-45504 PT ID: PT-

    Post summary

    The tweet announces discovery of a PoC/exploit for CVE-2026-45504, indicating exploitation potential but lacking detailed technical or mitigation information.

    1000089
    323 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-45504. 0day Intel: 🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-45504 PT ID: PT-

    Post summary

    A proof‑of‑concept/exploit for CVE‑2026‑45504 has been announced, but there is no evidence of active exploitation, patch information, or detailed technical data.

    10000131
    323 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    PoC

    Microsoft Exchange ServerのSSRF 脆弱性のPoC 公開-CVE-2026-45504 https://rocket-boys.co.jp/security-measures-lab/ms-exchange-server-ssrf-vulnerability-cve-2026-45504/ #セキュリティ対策Lab #security #securitynews

    Post summary

    A proof‑of‑concept for an SSRF vulnerability (CVE‑2026‑45504) in Microsoft Exchange Server has been published. No exploit tool, active exploitation, patch or debunking is referenced.

    00010191
    455 followersView on X
  • Abbey Joshua Oluwatayo@AbbeyCyberJo
    PoC

    Public PoC release for CVE-2026-45504 accelerates real-world exploitation risk for the many enterprises still running vulnerable on-premises Exchange servers, exposing them to easy file reads by any authenticated low-priv user via simple EWS manipulation. The flaw underscores ongoing issues with legacy on-prem software complexity and insufficient input validation in core components like WOPI handling, where low-privilege access should never enable arbitrary local file disclosure. Organizations should immediately apply Microsoft's June 2026 security updates, restrict outbound connections from Exchange servers, and accelerate migration to Exchange Online to reduce long-term attack surface.

    Post summary

    A public PoC for CVE-2026-45504 has been released, revealing that authenticated low‑priv users can read files via EWS on vulnerable Exchange servers; Microsoft has issued a June 2026 patch and recommends immediate application and additional mitigations.

    00010108
    219 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server_subscription_edition---

Explore more