CVE-2026-45502: Microsoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server Information Disclosure Vulnerability
Other sources
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.2562.045Patch KB5103212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1544.043Patch KB5103214 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.071Patch KB5103215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1748.048Patch KB5103213
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45502?
CVE-2026-45502 has a medium severity level rated at 5.
How do I fix CVE-2026-45502?
To remediate CVE-2026-45502, you should apply the necessary patches and security updates provided for Microsoft Exchange Server.
What systems are affected by CVE-2026-45502?
CVE-2026-45502 affects Microsoft Exchange Server 2019, Microsoft Exchange Server Subscription Edition RTM, and Microsoft Exchange Server 2016.
What does CVE-2026-45502 allow an attacker to do?
CVE-2026-45502 allows an authorized attacker to perform server-side request forgery, potentially disclosing sensitive information over a network.
Is CVE-2026-45502 an information disclosure vulnerability?
Yes, CVE-2026-45502 is classified as an information disclosure vulnerability due to its nature of allowing unauthorized information access.