CVE-2022-41040CISA KEVEPSS p100.0%

CVE-2022-41040Microsoft Exchange Server Server-Side Request Forgery Vulnerability

Microsoft / Exchange Server

Description

Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

Scoring

CVSS 8.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS99.96% probability of exploitation · percentile 100.0% · 2026-07-24T12:03:22Z
Last modified2026-06-17

CISA KEV entry

Added to KEV: 2022-09-30

(incoming)1

TypeTargetConfidenceTier
KEVEntryMicrosoft Exchange Server Server-Side Request Forgery Vulnerabilitykev-cve-2022-410400%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE
Microsoft Exchange Server Privilege Escalation Vulnerability
CVE
CVE-2026-45502
CVE
CVE-2026-45504
CVE
CVE-2026-45503
CVE
CVE-2026-26137
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.