Threat reportVulnerabilityTL-2026-1113
Microsoft Exchange SSRF Vulnerability (CVE-2026-45504) — Public PoC Exploit Enables Authenticated Arbitrary File Read
Microsoft Exchange SSRF Vulnerability (CVE-2026-45504) (TL-2026-1113) is a high-severity software vulnerability scored CVSS 8.8, first published 2026-07-05. It has no confirmed attribution, affects Microsoft Exchange Server 2016, references 1 CVE (CVE-2026-45504), maps to 16 MITRE ATT&CK techniques (T1005, T1027, T1068), and is covered by 9 detection rules and 18 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-1113
- Threat ID
- TL-2026-1113
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, financial-services, health, technology, legal, energy, education, manufacturing
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Microsoft Exchange SSRF Vulnerability (CVE-2026-45504)
Malware and tooling: hawktrace/CVE-2026-45504
How Microsoft Exchange SSRF Vulnerability (CVE-2026-45504) works
CVE-2026-45504 is a CVSS 8.8 server-side request forgery flaw in Microsoft Exchange's OneDriveProUtilities component (TryTwice/GetWacUrl functions) that lets an authenticated, low-privileged user craft an EWS ReferenceAttachment with a malicious ProviderEndpointUrl pointing to attacker infrastructure. Exchange fails to validate the URL scheme of the WOPI-returned WebApplicationUrl, allowing a file:// URI (hidden behind a fragment '#' trick) to be used for arbitrary local file read. HawkTrace publicly released a PoC exploit on GitHub on 2026-07-03; Microsoft had already patched the flaw on 2026-06-09.
CVE-2026-45504 is a server-side request forgery (SSRF) vulnerability affecting on-premises Microsoft Exchange Server 2016 (CU23), Exchange Server 2019 (CU14/CU15), and Exchange Server Subscription Edition (RTM builds prior to 15.02.2562.043). The root cause lies in Exchange's OneDriveProUtilities component, specifically the TryTwice and GetWacUrl helper functions used to build WAC (Web Application Companion / Office Online) document-preview URLs when a user interacts with a reference attachment.
An authenticated, low-privileged user can use Exchange Web Services (EWS) to create a ReferenceAttachment whose ProviderEndpointUrl points to an attacker-controlled HTTP server rather than a legitimate SharePoint/OneDrive/WOPI host. When the attachment is previewed, Exchange's backend issues a GetWopiTargetPropertiesByUrl request to that attacker-controlled endpoint to retrieve WOPI metadata. The malicious server responds with a crafted WebApplicationUrl field containing a file:// URI (for example, file:///C:/Windows/win.ini#) instead of a legitimate https:// WAC URL.
Because Exchange does not validate the URL scheme of the WebApplicationUrl value returned by the WOPI provider, it accepts the file:// scheme and proceeds to construct the final request. A '#' fragment character appended after the file path causes the URI parser to treat everything that follows (including OAuth access_token query parameters Exchange normally appends) as a fragment, which is discarded rather than appended to the path. Exchange then issues a FileWebRequest against the local filesystem path and returns the file's contents through the same response channel used for legitimate WAC previews — converting what starts as an SSRF primitive into a full arbitrary local file read on the Exchange server, achievable by any authenticated low-privileged mailbox user.
Security researchers at HawkTrace discovered and reported the flaw, and Microsoft addressed it in the June 9, 2026 Patch Tuesday cycle via KB5094139 (Subscription Edition RTM), KB5094142 (Exchange 2019 CU14), KB5094140 (Exchange 2019 CU15), and KB5094144 (Exchange 2016 CU23). Microsoft's initial exploitability assessment rated the issue 'Exploitation Less Likely.' On 2026-07-03, HawkTrace published a detailed technical write-up and a public proof-of-concept exploit on GitHub that automates malicious WOPI server setup, Exchange authentication, and arbitrary file requests (demonstrated against C:\Windows\win.ini), substantially lowering the barrier to exploitation for any unpatched, internet- or intranet-reachable Exchange server. There is no confirmed evidence of in-the-wild exploitation and the CVE does not currently appear in the CISA Known Exploited Vulnerabilities catalog, but the public, weaponized PoC materially raises near-term risk for organizations that have not yet applied the June 2026 updates, particularly those running Exchange 2016/2019 out of mainstream support and relying on the Extended Security Updates (ESU) program.
Post-exploitation, arbitrary local file read on an Exchange server can expose highly sensitive material — IIS/OWA web.config files containing connection strings and machine keys, certificate private key files, configuration data, and other artifacts that can be leveraged for further privilege escalation, credential theft, or full server/domain compromise — making this a high-value primitive even though the vulnerability itself does not include a code-execution step.
MITRE ATT&CK techniques used in TL-2026-1113
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1211 Exploitation for Stealth
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071.001 Web Protocols; T1090 Proxy
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Initial Access
T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment
Execution
Lateral Movement
T1210 Exploitation of Remote Services
Credential Access
T1552.001 Credentials In Files
Resource Development
T1583.004 Server; T1587.004 Exploits
Reconnaissance
Affected products and versions in Microsoft Exchange SSRF Vulnerability (CVE-2026-45504)
- Microsoft — Exchange Server 2016
Vulnerable versions: Cumulative Update 23 (pre-June 2026 update)
Fixed in: CU23 with KB5094144 - Microsoft — Exchange Server 2019
Vulnerable versions: Cumulative Update 14 (pre-update); Cumulative Update 15 (pre-update)
Fixed in: CU14 with KB5094142; CU15 with KB5094140 - Microsoft — Exchange Server Subscription Edition
Vulnerable versions: RTM builds prior to 15.02.2562.043
Fixed in: 15.02.2562.043 and later via KB5094139
Remediation for Microsoft Exchange SSRF Vulnerability (CVE-2026-45504)
Patches
- KB5094144 — Exchange Server 2016 CU23
- KB5094142 — Exchange Server 2019 CU14
- KB5094140 — Exchange Server 2019 CU15
- KB5094139 — Exchange Server Subscription Edition RTM
Immediate actions
- Apply the June 9, 2026 Exchange security updates (KB5094139, KB5094140, KB5094142, KB5094144) to all on-premises Exchange 2016, 2019, and Subscription Edition servers immediately given the public PoC.
- Restrict Exchange server outbound HTTP/HTTPS connectivity to only known, allowlisted WOPI/Office Online endpoints via firewall or forward-proxy egress rules.
- Review EWS/transport logs for ReferenceAttachment objects whose ProviderEndpointUrl references non-corporate or unexpected external hosts.
Workarounds
- Where patching cannot be applied immediately, restrict or disable outbound WOPI/WAC document-preview functionality if operationally acceptable.
- Block outbound connections from Exchange servers to untrusted or non-allowlisted external IP ranges and domains at the network perimeter.
Longer-term hardening
- Deploy network egress monitoring and proxy inspection for all outbound traffic originating from Exchange server roles.
- Enforce least-privilege mailbox and EWS application access policies to reduce the blast radius of any single compromised low-privilege account.
- Enroll out-of-mainstream-support Exchange 2016/2019 deployments in Microsoft's Extended Security Updates (ESU) program to continue receiving security patches.
- Plan migration to Exchange Online or a currently supported on-premises Exchange release to reduce long-term exposure to legacy WOPI/EWS attack surface.
CVEs associated with Microsoft Exchange SSRF Vulnerability (CVE-2026-45504)
CVE-2026-45504
Weaknesses (CWE) in Microsoft Exchange SSRF Vulnerability (CVE-2026-45504)
Timeline of Microsoft Exchange SSRF Vulnerability (CVE-2026-45504)
- Industry Patch Tuesday trackers (Zero Day Initiative, Brinqa, N-able) flag CVE-2026-45504 as one of seven Exchange Server CVEs — three spoofing, two information-disclosure, this elevation-of-privilege flaw, and one RCE — patched in a record 198-CVE June 2026 Patch Tuesday, advising administrators to apply the full Exchange update batch rather than triage individually.
- Qualys publishes mitigation/detection signatures covering CVE-2026-45504 the same day as Microsoft's fix, as part of its June 2026 Patch Tuesday security update review.
- Microsoft's initial MSRC exploitability assessment rates CVE-2026-45504 as 'Exploitation Less Likely' at the time of patch release.
- Security update KBs are published on Microsoft Support: KB5094139 (Subscription Edition RTM), KB5094142 (Exchange 2019 CU14), KB5094140 (Exchange 2019 CU15), and KB5094144 (Exchange 2016 CU23).
- Microsoft ships fixes for CVE-2026-45504 as part of the June 2026 Patch Tuesday cycle, addressing the Exchange Server SSRF / arbitrary file read (Elevation of Privilege) flaw.
- Cyber Security News reports that a public proof-of-concept exploit for CVE-2026-45504 is already circulating, noting Microsoft's initial 'Exploitation Less Likely' rating is being reconsidered as functional exploit code increases the likelihood of threat-actor adoption — over a week before HawkTrace's own GitHub PoC release.
- Additional outlets (GBHackers, CyberPress, Rankiteo) republish technical analysis of the SSRF/file-read exploitation chain, broadening awareness among defenders.
- Cyber Security News publishes coverage of the vulnerability and public PoC release, raising visibility and urgency for organizations running unpatched on-premises Exchange.
- HawkTrace publicly releases a working PoC exploit on GitHub that automates malicious WOPI server setup, Exchange authentication, and arbitrary local file read requests.
- HawkTrace publishes a detailed technical blog post, authored by researcher Batuhan Er, describing the OneDriveProUtilities/TryTwice/GetWacUrl root cause and the file:// fragment-bypass exploitation chain.
Sources cited for Microsoft Exchange SSRF Vulnerability (CVE-2026-45504)
- Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit
- CVE-2026-45504 Microsoft Exchange SSRF via File Read
- hawktrace/CVE-2026-45504 PoC exploit
- Microsoft Exchange SSRF Vulnerability Lets Low-Privileged Attackers Read Arbitrary Files
- CVE-2026-45504 - Security Update Guide - Microsoft Exchange Server Elevation of Privilege Vulnerability
- NVD - CVE-2026-45504
- PoC Released for Microsoft Exchange SSRF Flaw That Lets Low-Privileged Users Read Files
- Released: June 2026 Exchange Server Security Updates
- Description of the security update for Microsoft Exchange Server 2019 CU14: June 09, 2026 (KB5094142)
- Description of the security update for Microsoft Exchange Server 2016 CU23: June 09, 2026 (KB5094144)
- Description of the security update for Microsoft Exchange Server 2019 CU15: June 09, 2026 (KB5094140)
- Description of the security update for Microsoft Exchange Server Subscription Edition RTM: June 09, 2026 (KB5094139)
- June 2026 Patch Tuesday: Updates and Analysis
- Patch Tuesday - June 2026
- Microsoft: Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit
Detection coverage for TL-2026-1113
As of 2026-07-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1113 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.