Description
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Spoofing of internal network requests via server‑side request forgery
Action: Immediate Patch
AI Analysis

Impact

Server‑side request forgery in Microsoft Exchange Server permits an attacker who already has authorized access to fabricate requests that the server will forward to internal network resources. The vulnerability, identified by CWE‑918, can be exploited to acquire data from systems that are not exposed externally, potentially enabling further lateral movement or data exfiltration. The impact is confined to the scope of the authenticated user’s permissions, but can lead to unwanted otherwise inaccessible network endpoints being reached.

Affected Systems

This flaw affects Microsoft Exchange Server versions 2016 CU23, 2019 CU14, 2019 CU15, and the Subscription Edition released at RTM. All listed products are affected by the SSRF flaw and require the respective cumulative update to be applied.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. No EPSS value is provided and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not been observed to date. The attack requires the attacker to have valid credentials and the ability to send requests through the Exchange server; thus, privileged internal users constitute a potential threat vector. While the exploit is not ultra‑common, the typical SSA technique can be used in targeted attacks to bypass perimeter defenses.

Generated by OpenCVE AI on September 8, 2026 at 21:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative updates for Microsoft Exchange Server 2016 (CU23), 2019 (CU15 and CU14), and Subscription Edition RTM to patch the SSRF flaw.
  • Restrict outbound HTTP/HTTPS traffic from Exchange servers by applying firewall rules or proxy configurations that limit which internal services can be contacted.
  • Monitor exchange logs for anomalous outbound requests and review authentication patterns for signs of misuse.

Generated by OpenCVE AI on September 8, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Exchange Server 2016 Cumulative Update 23
Microsoft microsoft Exchange Server 2019 Cumulative Update 14
Microsoft microsoft Exchange Server 2019 Cumulative Update 15
Microsoft microsoft Exchange Server Subscription Edition Rtm
Vendors & Products Microsoft microsoft Exchange Server 2016 Cumulative Update 23
Microsoft microsoft Exchange Server 2019 Cumulative Update 14
Microsoft microsoft Exchange Server 2019 Cumulative Update 15
Microsoft microsoft Exchange Server Subscription Edition Rtm

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
Title Microsoft Exchange Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server 2016 Exchange Server 2019 Exchange Server Se Microsoft Exchange Server 2016 Cumulative Update 23 Microsoft Exchange Server 2019 Cumulative Update 14 Microsoft Exchange Server 2019 Cumulative Update 15 Microsoft Exchange Server Subscription Edition Rtm
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:42.500Z

Reserved: 2026-08-03T20:52:08.513Z

Link: CVE-2026-69361

cve-icon Vulnrichment

Updated: 2026-09-09T19:12:13.061Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:55.997

Modified: 2026-09-09T20:19:30.137

Link: CVE-2026-69361

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T04:15:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)