CVE-2026-65801
Microsoft · Microsoft Exchange Online
A server-side request forgery (SSRF) vulnerability in Microsoft Exchange Online allows an unauthenticated attacker to perform privilege escalation.
Executive summary
A critical server-side request forgery vulnerability in Microsoft Exchange Online permits unauthorized attackers to escalate privileges over a network.
Vulnerability
The flaw is a server-side request forgery (SSRF) which enables an unauthenticated attacker to manipulate requests, leading to unauthorized privilege escalation within the service.
Business impact
With a CVSS score of 10.0, this vulnerability poses an extreme threat to the confidentiality and integrity of email environments. Privilege escalation can allow an attacker to gain administrative control over the messaging platform, potentially leading to unauthorized data exfiltration or internal system manipulation.
Remediation
Immediate Action: Monitor the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65801 for specific instructions and apply all vendor-supplied fixes immediately.
Proactive Monitoring: Review administrative audit logs and monitor for unusual traffic patterns or unexpected requests originating from the Exchange Online environment.
Compensating Controls: Implement strict conditional access policies and ensure that cross-service communication is restricted to only necessary endpoints to reduce the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Security teams should treat this vulnerability with the highest urgency. Monitor the vendor advisory closely for updates and verify that all security configurations are aligned with current hardening guidance for cloud-based messaging services.