PoC Archive PoC Archive

tag

Exchange

  • CVE-2026-45504 web HIGH

    Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)

    CVE-2026-45504 is an authenticated arbitrary file read vulnerability in Microsoft Exchange Server. An attacker with valid mailbox credentials authenticates to OWA and, via the Exchange Web Services (EWS) CreateItem/CreateAttachment SOAP calls, creates a…

    Patched 2026-07-05
  • CVE-2026-42897 web MEDIUM 5.3 KEV EPSS 70%

    Exchange Health Checker Outbound Rule Blind Spot (CVE-2026-42897)

    CVE-2026-42897 describes a diagnostic blind spot in Exchange Health Checker. The analyzer only enumerates inbound IIS URL Rewrite rules and ignores outbound rules. The EOMT mitigation for this CVE installs an outbound Content-Security-Policy rewrite rule…

    Unverified 2026-05-15