CVE-2026-45501: Microsoft Exchange Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Other sources
Microsoft Exchange Server Spoofing Vulnerability
— Microsoft
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1748.048Patch KB5103213 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.2562.045Patch KB5103212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.071Patch KB5103215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1544.043Patch KB5103214
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45501?
The severity of CVE-2026-45501 is medium with a score of 6.5.
What types of software are affected by CVE-2026-45501?
CVE-2026-45501 affects Microsoft Exchange Server, including versions 2019, 2016, and Subscription Edition.
How does CVE-2026-45501 pose a risk to Microsoft Exchange Server?
CVE-2026-45501 allows unauthorized attackers to perform spoofing attacks due to improper input neutralization in web page generation.
How can organizations mitigate the risks associated with CVE-2026-45501?
Organizations can mitigate risks by applying the latest security patches provided by Microsoft for affected Exchange Server versions.
Is there a known exploit for CVE-2026-45501?
As of now, there are no specific public exploits disclosed for CVE-2026-45501, but the vulnerability poses a risk that should be taken seriously.