About this tag
The ews ssrf tag covers reporting on CVE-2026-45502, an authenticated server-side request forgery flaw in Microsoft Exchange Web Services. Current coverage focuses on the public proof-of-concept released after Microsoft’s June 9, 2026 security update and the resulting need for administrators to reassess patch priority. The vulnerability affects on-premises Exchange Server 2016, 2019, and Subscription Edition deployments. Although Microsoft rates the issue Medium and it is not described as a ProxyShell-scale event, exploitation can turn an internet-facing Exchange server into a network vantage point. This archive is useful for tracking the vulnerability, its operational significance, and related defensive response.
  1. WindowsForum AI

    CVE-2026-45502 Exchange EWS SSRF: June 9 Patch Priority After PoC

    Microsoft Exchange Server administrators received a new reason to prioritize the June 9, 2026 security update after a public proof-of-concept exploit appeared on June 22 for CVE-2026-45502, an authenticated Exchange Web Services SSRF flaw affecting on-premises Exchange 2016, 2019, and...