Server-Side Request Forgery (SSRF) in Microsoft Exchange Server - CVE-2026-69361
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to server-side request forgery (ssrf) in Microsoft Exchange Server when processing a specially crafted internet calendar subscription. A remote user can submit a specially crafted internet calendar subscription to disclose sensitive information.
The affected server can be induced to send HTTP requests to internal or loopback systems.