CVE-2026-45504: Public PoC Exploit Released
CVE-2026-45504 is a low-privileged, authenticated Exchange mailbox user can trick on-prem Exchange into reading arbitrary local files (config files, credential material) via a WOPI/WAC URL-parsing flaw. Microsoft patched it June 9, 2026. A public PoC dropped June 24, 2026. If you haven't patched, do it now, exploitability just went from "less likely" to "trivial." Summary [...]










