CVE-2026-45583: Microsoft Exchange Server Remote Code Execution Vulnerability

Overview

Severity
High (CVSS 7.5)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Jun
Released
2026-06-09

Description

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

FAQ

According to the CVSS metric, the attack complexity is high (AC:H). What does this mean for this vulnerability? Exploitation depends on an attacker being able to place themselves in a machine‑in‑the‑middle position on the network during use of the affected script. Because this requires specific network conditions that are not commonly present, the vulnerability is more difficult to exploit than issues that can be triggered directly. How could an attacker exploit this vulnerability? An attacker who is able to intercept network traffic could interfere with the secure connection used by the Exchange migration script and inject malicious data. When the script is run during a hybrid migration, this could cause unintended commands to run on the on‑premises Exchange server with administrative permissions. Is there anything to be done in addition to installing the June 2026 security updates for my Exchange Server? Yes, Microsoft recommends that customers download and use the latest, fixed version of the Public Folder scripts. The versions of the Public Folder scripts included with Exchange Server are outdated and will be removed in a future update. Customers can download the latest version of the Public Folder scripts here.

Affected Products (4)

ESU

  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 14
  • Microsoft Exchange Server 2019 Cumulative Update 15

Server Software

  • Microsoft Exchange Server Subscription Edition RTM

Security Updates (1)

Acknowledgments

Anonymous

Revision History

  • 2026-06-09: Information published.