Microsoft · Exchange Server · CVE-2026-45502
**Name of the Vulnerable Software and Affected Versions**
Microsoft Exchange Server 2016 CU23
Microsoft Exchange Server 2019 CU14
Microsoft Exchange Server 2019 CU15
Microsoft Exchange Server SE
**Description**
Microsoft Exchange Server contains a Server-Side Request Forgery (SSRF) flaw, which occurs when a server fails to properly validate requests. This allows an authorized mailbox user to force the server to make HTTP requests to internal networks, enabling internal network reconnaissance and the disclosure of sensitive information from internal HTTP services. The issue stems from the fact that intranet address validation is gated on the `isBposUser` variable, which is always `false` for on-premises installations, causing them to skip the security check entirely. Exploitation is achieved via a SOAP request to the EWS InstallApp endpoint using a crafted `ManifestUrl` parameter.
**Recommendations**
Update Microsoft Exchange Server 2016 CU23 to the June 2026 SU.
Update Microsoft Exchange Server 2019 CU14 to the June 2026 SU.
Update Microsoft Exchange Server 2019 CU15 to the June 2026 SU.
Update Microsoft Exchange Server SE to the June 2026 SU.