Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-65801: Microsoft Exchange Online lets attackers gain higher access
CVE-2026-65801 · published 14 days ago
Summary
The cloud email service Microsoft Exchange Online can be tricked into contacting internal systems, allowing an outsider to raise their access level. This could let an attacker see or change sensitive information. Apply the latest Microsoft updates, enable strong authentication, and watch for unusual activity on your email accounts.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | microsoft exchange online | - |
Original advisory text
Microsoft Exchange Online Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65801 vendor-advisory patch
Severity
10.0
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-918Server-Side Request Forgery (SSRF)
Timeline
Published20 Aug 2026
Updated3 Sep 2026
First seen20 Aug 2026
Monitor software like this
Free during beta