PoC Released for Microsoft Exchange Server EWS InstallApp SSRF Vulnerability
ID: 89667b85-7f8d-57f4-9f32-34acd5755b79
STIX ID: report--89667b85-7f8d-57f4-9f32-34acd5755b79
Feed Name: GBHackers
A proof-of-concept SSRF vulnerability (CVE-2026-45502) in Microsoft Exchange Server’s EWS InstallApp allows authenticated mailbox users to force the server to make HTTP requests to attacker-controlled or internal endpoints (including metadata services); affected builds include Exchange 2016 CU23, 2019 CU14/CU15 and Subscription Edition RTM, and Microsoft released fixes on June 9, 2026—organisations should apply patches, restrict Exchange outbound access, and monitor anomalous HTTP traffic originating from Exchange.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
