tag
Exchange
CVE-2026-45504
web
HIGH
Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)
CVE-2026-45504 is an authenticated arbitrary file read vulnerability in Microsoft Exchange Server. An attacker with valid mailbox credentials authenticates to OWA and, via the Exchange Web Services (EWS) CreateItem/CreateAttachment SOAP calls, creates a…
Patched
2026-07-05
CVE-2026-42897
web
MEDIUM 5.3
KEV
EPSS 70%
Exchange Health Checker Outbound Rule Blind Spot (CVE-2026-42897)
CVE-2026-42897 describes a diagnostic blind spot in Exchange Health Checker. The analyzer only enumerates inbound IIS URL Rewrite rules and ignores outbound rules. The EOMT mitigation for this CVE installs an outbound Content-Security-Policy rewrite rule…
Unverified
2026-05-15