CVE-2026-54998General(microsoft / exchange_online)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch microsoft exchange_online systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_online

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 4 mentions (2026-07-03); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
exchange_online

1 version affected across 1 product

Deep dive

Activity timeline10 mentions / 5d
01234Mentions · 2026-07-02: 1Mentions · 2026-07-03: 4Mentions · 2026-07-07: 2Mentions · 2026-07-11: 2Mentions · 2026-07-31: 1Active Exploitation · 2026-07-03: 1Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-03: 2Technical Details · 2026-07-07: 207-0207-0307-0707-1107-31
Signal classification4 categories
General
440.0%
Disclosure
330.0%
Patch
220.0%
Active Exploitation
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-07-021
Disclosure1
2026-07-034
Active Exploitation1Disclosure1General1Patch1
2026-07-072
Disclosure1Patch1
2026-07-112
General2
2026-07-311
General1
Full discourse10 posts
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 7. 2 Microsoft Exchange Online Elevation of Privilege Vulnerability CVE-2026-54998 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54998

    Post summary

    The tweet announces Microsoft’s security update for CVE-2026-54998, an elevation‑of‑privilege flaw in Exchange Online, providing a link to the official Microsoft page without offering exploit details or patch instructions.

    1010079
    91 followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    CVSS 8.8. CVE-2026-54998. Worth reading before your users find out the hard way. Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a... Stay ahead of the curve.

    Post summary

    The post discloses CVE-2026-54998 with a CVSS of 8.8, noting an authorization flaw in Microsoft Exchange Online that allows privilege escalation for authorized attackers.

    0000176
    335 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-54998: Microsoft Exchange Online Incorrect Authorization Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04rwKQS0

    Post summary

    The text only lists a CVE title and a link, lacking explicit details on exploitation, mitigation, or technical specifics. No strong indicators for any other category are present.

    0000048
    31 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-54998 Microsoft Exchange Onlineの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/10/cve-2026-54998-microsoft-exchange-online/ #IT #Security #cybersecurity

    Post summary

    The post advertises a blog article that explains CVE‑2026‑54998 and summarizes its impact and countermeasures, but it provides no concrete technical details, PoC, exploitation evidence, or patch information.

    0000065
    206 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-54998 Microsoft Exchange Onlineの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/10/cve-2026-54998-microsoft-exchange-online/ #IT #Security #cybersecurity

    Post summary

    A blog post announces the Microsoft Exchange Online vulnerability CVE-2026-54998 and promises an explanation of its impact and countermeasures, but provides no detailed technical information or exploit specifics.

    0000072
    206 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-54998 (CVSS 8.8) Microsoft Exchange Online privilege escalation flaw. Authorized attackers can elevate privileges over network. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #CyberSecurity https://t.co/V6lFDQNnP2

    Post summary

    The tweet warns of a high‑severity Microsoft Exchange Online privilege escalation vulnerability (CVE‑2026‑54998) and urges users to patch immediately.

    0000085
    66 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-54998 (CVSS 8.8): incorrect authorization in Microsoft Exchange Online permits privilege escalation. Review Microsoft 365 tenant and apply updates promptly. https://nvd.nist.gov/vuln/deta… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/nKX3nzVr5F

    Post summary

    The tweet highlights CVE‑2026‑54998 with a CVSS of 8.8, warns of privilege escalation via incorrect authorization in Microsoft Exchange Online, and urges users to review their Microsoft 365 tenant and apply the necessary updates.

    0000055
    92 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    It is possible to see elevated activities targeting Microsoft Exchange Online (CVE-2026-54998) https://vuldb.com/vuln/376012/cti

    Post summary

    The post references potential elevated activity against Microsoft Exchange Online linked to CVE‑2026‑54998, indicating possible active exploitation but without detailed evidence.

    0000098
    2.3K followersView on X
  • VulDB 🛡@vuldb
    General

    A new vulnerability with increased severity was disclosed for Microsoft Exchange Online (CVE-2026-54998) https://vuldb.com/vuln/376012

    Post summary

    The text announces a new Microsoft Exchange Online vulnerability (CVE-2026-54998) with increased severity but provides no details on exploitation, patches, or technical specifics.

    00000126
    2.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54998 Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-54998

    Post summary

    The post merely announces CVE-2026-54998, describing an incorrect authorization issue that enables privilege escalation in Microsoft Exchange Online, without providing PoC, exploit code, or patch information.

    00000730
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_online---

Explore more