Microsoft · Exchange Server · CVE-2026-45501
**Name of the Vulnerable Software and Affected Versions**
Microsoft Exchange Server (affected versions not specified)
**Description**
Microsoft Exchange Server contains a server-side request forgery (SSRF) issue, which occurs when a server fails to properly validate requests. This allows an authorized attacker to perform spoofing over a network. Additionally, incorrect input neutralization during the generation of web pages may lead to cross-site scripting (XSS), a technique where malicious scripts are injected into trusted websites, further enabling identity spoofing.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.