Impact
Server‑side request forgery (SSRF) in Microsoft Exchange Server, as detailed in the updated description, permits an authorized attacker to perform spoofing over a network. By sending crafted requests that the server forwards internally, the attacker can forge network communications and potentially compromise authentication or data integrity, ultimately allowing the corruption or interception of legitimate traffic.
Affected Systems
The vulnerability affects Microsoft Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Update 14, Exchange Server 2019 Cumulative Update 15, and Exchange Server Subscription Edition RTM. All listed versions remain vulnerable until the corresponding cumulative update or patch for CVE‑2026‑45501 is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is less than 1% (~0.003) and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is network‑based; a user with valid credentials can trigger the SSRF flaw by sending requests that the server forwards internally, enabling spoofed communications. Because it requires authorized access, the risk is elevated in environments with exposed authenticated users, but applying vendor patch remains the only definitive mitigation.
OpenCVE Enrichment