logo

PoC Exploit Released for Microsoft Exchange Server Elevation of Privilege Vulnerability

ID: 6f33fa49-4bf6-5174-8fa9-02f82a97e23b

STIX ID: report--6f33fa49-4bf6-5174-8fa9-02f82a97e23b

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Abinaya

...
...

CVE-2026-45504 is a high-severity SSRF-related vulnerability in on-premises Microsoft Exchange 2016/2019 that allows a low-privileged authenticated user to induce the server to perform local file reads (via a crafted WOPI WebApplicationUrl using file:// and a fragment), enabling credential/config exfiltration and privilege escalation; a public PoC exists and Microsoft released security updates on June 9, 2026—administrators should urgently patch, restrict outbound access, and monitor unusual WOPI/EWS activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.