Security Updates for Microsoft Exchange Server (June 2026)

high Nessus Plugin ID 320863

Synopsis

The Microsoft Exchange Server installed on the remote host is affected by multiple vulnerabilities.

Description

The Microsoft Exchange Server installed on the remote host is missing a security update. It is, therefore, affected by multiple vulnerabilities as referenced in the June, 2026 security bulletin.

- Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. (CVE-2026-45500, CVE-2026-45501, CVE-2026-47631)

- Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. (CVE-2026-48579)

- Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. (CVE-2026-45583)

- Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. (CVE-2026-45502, CVE-2026-45503)

- Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. (CVE-2026-45504)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Microsoft has released the following security updates to address this issue:
-KB5094139
-KB5094140
-KB5094142
-KB5094144

See Also

http://www.nessus.org/u?496cae11

http://www.nessus.org/u?6823ab4e

http://www.nessus.org/u?3b89f8a8

http://www.nessus.org/u?629d2e81

Plugin Details

Severity: High

ID: 320863

File Name: smb_nt_ms26_jun_exchange.nasl

Version: 1.1

Type: Local

Agent: windows

Published: 6/12/2026

Updated: 6/12/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: High

Base Score: 9.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-47631

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2026-45583

Vulnerability Information

CPE: cpe:/a:microsoft:exchange_server:subscription_edition, cpe:/a:microsoft:exchange_server:2016, cpe:/a:microsoft:exchange_server:2019

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Patch Publication Date: 6/9/2026

Vulnerability Publication Date: 6/4/2026

Reference Information

CVE: CVE-2026-42897, CVE-2026-45500, CVE-2026-45501, CVE-2026-45502, CVE-2026-45503, CVE-2026-45504, CVE-2026-45583, CVE-2026-47631, CVE-2026-48579

IAVA: 2026-A-0572

MSFT: MS26-5094139, MS26-5094140, MS26-5094142, MS26-5094144

MSKB: 5094139, 5094140, 5094142, 5094144