AI analysis
CVE-2026-65801 is a server-side request forgery (CWE-918) in Microsoft's cloud-hosted Exchange Online service that an unauthorized attacker can reach over the network without credentials or user interaction. A crafted request causes Exchange Online server components to issue requests toward internal service endpoints, and the scope-changed CVSS 3.1 vector (S:C with high confidentiality, integrity, and availability impact) indicates the resulting privilege elevation extends beyond the initially targeted component. A successful attacker gains elevated privileges within the Exchange Online service, potentially enabling broader access to mailbox data and service functionality. All organizations with mailboxes hosted in Exchange Online are in scope; because this is a flaw in Microsoft's managed service, customers cannot patch it themselves and depend on Microsoft's service-side remediation. Exploitation has not been publicly confirmed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.
What to do: Monitor the MSRC advisory for CVE-2026-65801 and the Microsoft 365 admin center Message Center for Microsoft's service-side fix and remediation timeline; no customer-side patch or version upgrade applies. Until remediation is confirmed, review Exchange Online audit logs (Unified Audit Log) for anomalous privilege changes or unusual server-side activity, and report any suspected exploitation to MSRC.
Affected
| Microsoft Exchange Online (hosted cloud service) | Microsoft-managed cloud service; no customer-deployed version numbers apply (none provided in the data) |
Estimated exposure
masshundreds of millions of mailboxes across Microsoft 365 tenants (the entire hosted Exchange Online service is in scope) — Estimate is based on Microsoft's publicly reported installed base of hundreds of millions of Microsoft 365 paid seats, most of which rely on Exchange Online mailboxes, with a service-side flaw affecting the hosted platform as a whole…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.