ZeroHour

CVE-2026-65801

mass

SSRF Privilege Elevation in Microsoft Exchange Online

CVSS 3.1
10.0 critical
EPSS
<1%p42
Published
()
Modified
AI analysis

CVE-2026-65801 is a server-side request forgery (CWE-918) in Microsoft's cloud-hosted Exchange Online service that an unauthorized attacker can reach over the network without credentials or user interaction. A crafted request causes Exchange Online server components to issue requests toward internal service endpoints, and the scope-changed CVSS 3.1 vector (S:C with high confidentiality, integrity, and availability impact) indicates the resulting privilege elevation extends beyond the initially targeted component. A successful attacker gains elevated privileges within the Exchange Online service, potentially enabling broader access to mailbox data and service functionality. All organizations with mailboxes hosted in Exchange Online are in scope; because this is a flaw in Microsoft's managed service, customers cannot patch it themselves and depend on Microsoft's service-side remediation. Exploitation has not been publicly confirmed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.

What to do: Monitor the MSRC advisory for CVE-2026-65801 and the Microsoft 365 admin center Message Center for Microsoft's service-side fix and remediation timeline; no customer-side patch or version upgrade applies. Until remediation is confirmed, review Exchange Online audit logs (Unified Audit Log) for anomalous privilege changes or unusual server-side activity, and report any suspected exploitation to MSRC.

Affected
Microsoft Exchange Online (hosted cloud service)Microsoft-managed cloud service; no customer-deployed version numbers apply (none provided in the data)
Estimated exposure
masshundreds of millions of mailboxes across Microsoft 365 tenants (the entire hosted Exchange Online service is in scope) — Estimate is based on Microsoft's publicly reported installed base of hundreds of millions of Microsoft 365 paid seats, most of which rely on Exchange Online mailboxes, with a service-side flaw affecting the hosted platform as a whole…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
exchange online
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

September 2026 Patch Tuesday forecast: All we need is more time

September 2026 Patch Tuesday forecast expects record CVE volume after August's 398 fixes, with SharePoint flaws CVE-2026-55040 and CVE-2026-63520 actively exploited.

This Patch Tuesday forecast column notes August 2026 Patch Tuesday was the second largest ever with 398 resolved CVEs, yet only one was confirmed actively exploited. SharePoint flaws CVE-2026-55040 and CVE-2026-63520 are being chained for authentication bypass and remote code execution in active attacks against unpatched servers. Microsoft Defender's ShieldBreak elevation of privilege flaw (CVE-2026-69414) is publicly disclosed with PoC code and a fix is expected, while Chrome CVE-2026-85046 was reported exploited in the wild. Several products, including Windows 11 24H2 Home/Pro and Exchange Server 2016/2019 ESU, reach end of support in October 2026.

Help Net Security · 6d agoAdvisory in the wildCVE-2026-55040CVE-2026-63520CVE-2026-62911+5 CVEs1