PoC Exploit Released for Microsoft Exchange Server Elevation of Privilege Vulnerability
ID: 6f33fa49-4bf6-5174-8fa9-02f82a97e23b
STIX ID: report--6f33fa49-4bf6-5174-8fa9-02f82a97e23b
Feed Name: cybersecurityNews.com
CVE-2026-45504 is a high-severity SSRF-related vulnerability in on-premises Microsoft Exchange 2016/2019 that allows a low-privileged authenticated user to induce the server to perform local file reads (via a crafted WOPI WebApplicationUrl using file:// and a fragment), enabling credential/config exfiltration and privilege escalation; a public PoC exists and Microsoft released security updates on June 9, 2026—administrators should urgently patch, restrict outbound access, and monitor unusual WOPI/EWS activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
