Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploit Released for Microsoft Exchange Vulnerability

Exploit Released for Microsoft Exchange Vulnerability

Posted on June 25, 2026 By CWS

A newly released proof-of-concept exploit targets a critical server-side request forgery vulnerability, CVE-2026-45504, in Microsoft Exchange Server. This flaw allows for privilege escalation through unauthorized file reads, posing significant security risks.

Affected Systems and Vulnerability Details

The vulnerability impacts on-premises versions of Exchange Server 2016 and 2019, including the Subscription Edition. Microsoft addressed this issue in their June 9, 2026, security updates. The flaw originates from the interaction between Exchange, SharePoint, and WOPI for generating document preview URLs via WAC.

Exchange employs functions like GetTokenRequestWebResponse and GetWacUrl, which utilize OneDriveProUtilities.TryTwice to handle HTTP requests based on URLs controlled by attackers. The lack of URL scheme validation in the WebApplicationUrl field allows attackers to introduce non-HTTP schemes, facilitating the creation of malicious WAC URLs.

Exploit Mechanism and Impact

The absence of validation transforms SSRF vulnerabilities into powerful tools for unauthorized file access on the Exchange server. The exploit utilizes a URI-handling trick with the fragment character ‘#’. By returning a crafted WebApplicationUrl, such as file:///C:/windows/win.ini#, attackers can manipulate the URL to bypass URI parsers and access local files.

This technique enables attackers to extract sensitive data, including configuration files and credentials, which can lead to further system compromise. A low-privileged Exchange account with server access is sufficient for an attacker to execute this exploit, particularly using Exchange Web Services to direct requests to a malicious endpoint.

Security Measures and Recommendations

Microsoft rates this as an elevation of privilege vulnerability with a CVSS score of 8.8, indicating high risk. Security updates are available for Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Updates 14 and 15, and Subscription Edition RTM. These updates are critical to mitigate the exploit’s impact.

Administrators should urgently apply these updates and confirm their servers match the updated build numbers. In the interim, organizations can reduce risk by securing Exchange and EWS endpoints, restricting outbound traffic, and monitoring for unusual WOPI/WAC token requests or unexpected local file access.

Although Microsoft initially assessed the exploit as unlikely, the public release of functional code increases the likelihood of attacks on unpatched systems. Vigilant monitoring for suspicious activity is essential to detect and prevent exploitation attempts in the wild.

Cyber Security News Tags:CVE-2026-45504, Cybersecurity, Exchange Server, Exchange Web Services, Exploit, IT security, Microsoft Exchange, privilege escalation, security patch, security update, server-side request forgery, SSRF, Vulnerability, WOPI

Post navigation

Previous Post: Malicious App on Google Play Poses Serious Security Threat
Next Post: Mass Exploit Targets Laravel Livewire Apps for Credential Theft

Related Posts

Top Zero-Day Vulnerabilities Exploited in the Wild in 2025 Top Zero-Day Vulnerabilities Exploited in the Wild in 2025 Cyber Security News
New Battering RAM Attack Bypasses Latest Defenses on Intel and AMD Cloud Processors New Battering RAM Attack Bypasses Latest Defenses on Intel and AMD Cloud Processors Cyber Security News
Microsoft Investigating Forms Service Issue Not Accessible for Users Microsoft Investigating Forms Service Issue Not Accessible for Users Cyber Security News
Fake CERT-UA Website Distributes Go-Based Malware Fake CERT-UA Website Distributes Go-Based Malware Cyber Security News
Apache Log4j Vulnerability Allow Attackers to Intercept Sensitive Log Data Apache Log4j Vulnerability Allow Attackers to Intercept Sensitive Log Data Cyber Security News
China-Nexus APT Group Leverages DLL Sideloading Technique to Attack Government and Media Sectors China-Nexus APT Group Leverages DLL Sideloading Technique to Attack Government and Media Sectors Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic Alleges Alibaba’s Unauthorized Access to AI Models
  • Mass Exploit Targets Laravel Livewire Apps for Credential Theft
  • Exploit Released for Microsoft Exchange Vulnerability
  • Malicious App on Google Play Poses Serious Security Threat
  • Cyber Attack Uses Fake Microsoft Teams Alerts to Breach Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic Alleges Alibaba’s Unauthorized Access to AI Models
  • Mass Exploit Targets Laravel Livewire Apps for Credential Theft
  • Exploit Released for Microsoft Exchange Vulnerability
  • Malicious App on Google Play Poses Serious Security Threat
  • Cyber Attack Uses Fake Microsoft Teams Alerts to Breach Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark