CVE-2026-69361: Microsoft Exchange Server Spoofing Vulnerability

Overview

Severity
Medium (CVSS 6.5)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Sep
Released
2026-09-08

Description

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

FAQ

What is the nature of the spoofing? An authenticated attacker could cause an affected Exchange server to send HTTP requests to internal or loopback systems by submitting a specially crafted internet calendar subscription. Successful exploitation could expose sensitive information returned as valid calendar content from resources reachable by the server. According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated using valid Exchange user credentials.

Affected Products (4)

ESU

  • Microsoft Exchange Server 2019 Cumulative Update 14
  • Microsoft Exchange Server 2019 Cumulative Update 15
  • Microsoft Exchange Server 2016 Cumulative Update 23

Server Software

  • Microsoft Exchange Server Subscription Edition RTM

Security Updates (1)

Acknowledgments

<a href="https://www.linkedin.com/in/navaponpremkasem/">71C4</a>

Revision History

  • 2026-09-08: Information published.