Description
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-08-20
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Exchange Online is vulnerable to a server‑side request forgery (SSRF) that allows an unauthenticated attacker to elevate privileges across the network. This flaw is a CWE-918 vulnerability, rated as CVSS 10, and permits the attacker to bypass authentication controls, access privileged endpoints, and potentially execute arbitrary actions within the tenant. This can lead to full compromise of the organization’s email and collaboration services.

Affected Systems

The affected product is Microsoft Exchange Online. No specific version information was provided, so all instances of Exchange Online are potentially vulnerable until Microsoft releases a fix.

Risk and Exploitability

The CVSS score of 10 indicates that the vulnerability is critical. EPSS data is not available, but because the flaw is a SSRF that enables privilege escalation, the likelihood of exploitation remains high. While the vulnerability is not yet listed in the CISA KEV catalog, the absence of that designation does not reduce its risk. Attackers can induce Exchange Online to make outbound requests to arbitrary internal or external hosts, which the server then uses to reach privileged internal interfaces. By controlling the payload of those requests, an attacker can impersonate a privileged user and gain elevated rights.

Generated by OpenCVE AI on August 21, 2026 at 01:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Exchange Online security update for CVE‑2026‑65801.
  • Configure firewall or conditional access rules to restrict outbound traffic from Exchange Online to only trusted hosts.
  • Enforce the principle of least privilege for service accounts and review any high‑privilege service endpoints within Exchange Online settings.

Generated by OpenCVE AI on August 21, 2026 at 01:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:exchange_online:-:*:*:*:*:*:*:*

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Exchange Online Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft exchange Online
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:exchange_online:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Online
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Online
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:34:35.406Z

Reserved: 2026-07-22T21:36:47.629Z

Link: CVE-2026-65801

cve-icon Vulnrichment

Updated: 2026-08-21T11:19:30.531Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:17:54.897

Modified: 2026-08-24T17:47:29.477

Link: CVE-2026-65801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T01:15:07Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)