PT-2026-47974 · Microsoft · Exchange Server

·

CVE-2026-45502

·

Published

2026-06-09

·

Updated

2026-07-28

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server 2016 CU23 Microsoft Exchange Server 2019 CU14 Microsoft Exchange Server 2019 CU15 Microsoft Exchange Server SE
Description Microsoft Exchange Server contains a Server-Side Request Forgery (SSRF) flaw, which occurs when a server fails to properly validate requests. This allows an authorized mailbox user to force the server to make HTTP requests to internal networks, enabling internal network reconnaissance and the disclosure of sensitive information from internal HTTP services. The issue stems from the fact that intranet address validation is gated on the isBposUser variable, which is always false for on-premises installations, causing them to skip the security check entirely. Exploitation is achieved via a SOAP request to the EWS InstallApp endpoint using a crafted ManifestUrl parameter.
Recommendations Update Microsoft Exchange Server 2016 CU23 to the June 2026 SU. Update Microsoft Exchange Server 2019 CU14 to the June 2026 SU. Update Microsoft Exchange Server 2019 CU15 to the June 2026 SU. Update Microsoft Exchange Server SE to the June 2026 SU.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08292
CVE-2026-45502

Affected Products

Exchange Server