CVE-2026-45503: Microsoft Exchange Server Information Disclosure Vulnerability
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
Other sources
Microsoft Exchange Server Information Disclosure Vulnerability
— Microsoft
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1748.048Patch KB5103213 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1544.043Patch KB5103214 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.2562.045Patch KB5103212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.071Patch KB5103215
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45503?
CVE-2026-45503 has a severity rating of high with a score of 8.1.
How does CVE-2026-45503 affect Microsoft Exchange Server?
CVE-2026-45503 allows an authorized attacker to disclose sensitive information over the network due to improper authorization.
What versions of Microsoft Exchange Server are impacted by CVE-2026-45503?
CVE-2026-45503 affects Microsoft Exchange Server 2019, 2016, and the Subscription Edition RTM.
What type of vulnerability is CVE-2026-45503?
CVE-2026-45503 is categorized as a Server-side Request Forgery (SSRF) vulnerability.
How do I mitigate CVE-2026-45503 in my environment?
To mitigate CVE-2026-45503, it is recommended to apply the latest security updates from Microsoft for affected Exchange Server versions.