Microsoft Exchange Vulnerability CVE-2026-45504 Gets Public PoC Exploit
ID: 1661d464-ef3d-5f14-8aec-4239d2d9f229
STIX ID: report--1661d464-ef3d-5f14-8aec-4239d2d9f229
Feed Name: securityonline.info
Threat Score
Researchers disclosed CVE-2026-45504, a high-severity (CVSS 8.8) Microsoft Exchange Server vulnerability that allows a low-privileged mailbox user to force the server to read arbitrary local files via malicious WOPI/SharePoint preview URLs; public proof-of-concept code is available and Microsoft released fixes in the June 2026 updates (apply KB5094144/KB5094142/KB5094140/KB5094139 for affected builds).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
