logo

Microsoft Exchange Vulnerability CVE-2026-45504 Gets Public PoC Exploit

ID: 1661d464-ef3d-5f14-8aec-4239d2d9f229

STIX ID: report--1661d464-ef3d-5f14-8aec-4239d2d9f229

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-07-03

Date Updated: 2026-08-06

Author: Do Son

ADMIRALTY:B6
...
...

Researchers disclosed CVE-2026-45504, a high-severity (CVSS 8.8) Microsoft Exchange Server vulnerability that allows a low-privileged mailbox user to force the server to read arbitrary local files via malicious WOPI/SharePoint preview URLs; public proof-of-concept code is available and Microsoft released fixes in the June 2026 updates (apply KB5094144/KB5094142/KB5094140/KB5094139 for affected builds).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.