Skip to content

CVE-2026

Api.Msrc.Microsoft September 8, 2026

We use optional cookies to improve your experience on our websites, such as through social media connections, and to display personalized advertising based on your online activity. If you reject optional cookies, only cookies necessary to provide you the services will be used. You may change your selection by clicking “Manage Cookies” at the bottom of the page. Privacy Statement Third-Party Cookies

Released: Sep 8, 2026

Please see Common Vulnerability Scoring System for more information on the definition of these metrics.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

The following table provides an exploitability assessment for this vulnerability at the time of original publication.

What is the nature of the spoofing?

An authenticated attacker could cause an affected Exchange server to send HTTP requests to internal or loopback systems by submitting a specially crafted internet calendar subscription. Successful exploitation could expose sensitive information returned as valid calendar content from resources reachable by the server.

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?

The attacker must be authenticated using valid Exchange user credentials.

To determine the support lifecycle for your software, see the Microsoft Support Lifecycle .

Information published.