Home

Description

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

PUBLISHED Reserved 2026-05-12 | Published 2026-06-09 | Updated 2026-06-10 | Assigner microsoft




HIGH: 7.5CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Problem types

CWE-94: Improper Control of Generation of Code ('Code Injection')

Product status

15.01.0.0 (custom) before 15.01.2507.069
affected

15.02.0.0 (custom) before 15.02.1544.041
affected

15.02.0.0 (custom) before 15.02.1748.046
affected

15.02.0.0 (custom) before 15.02.2562.043
affected

References

msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45583 (Microsoft Exchange Server Remote Code Execution Vulnerability) vendor-advisory patch

cve.org (CVE-2026-45583)

nvd.nist.gov (CVE-2026-45583)

Download JSON