CVE-2026-45504: Public PoC Exploit Released
Stewart Moncrieff2026-06-30T10:54:32-04:00CVE-2026-45504 is a low-privileged, authenticated Exchange mailbox user can trick on-prem Exchange into reading arbitrary local files (config files, credential material) via a WOPI/WAC URL-parsing flaw. Microsoft patched it June 9, 2026. A public PoC dropped June 24, 2026. If you haven't patched, do it now, exploitability just went from "less likely" to "trivial." Summary [...]











