CVE-2026-65801Patch(microsoft / exchange_online)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft exchange_online systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_online

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-08-21); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
exchange_online

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-08-21: 2Mentions · 2026-08-23: 1Mentions · 2026-08-24: 1Mentions · 2026-08-25: 1Mentions · 2026-08-26: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-23: 1Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-23: 1Technical Details · 2026-08-24: 1Technical Details · 2026-08-25: 1Technical Details · 2026-08-26: 108-2108-2308-2408-2508-26
Signal classification3 categories
Patch
350.0%
General
233.3%
Disclosure
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-212
General1Patch1
2026-08-231
Patch1
2026-08-241
Patch1
2026-08-251
Disclosure1
2026-08-261
General1
Full discourse6 posts
  • lee1981@lee1981b
    Disclosure

    🔥 CyberForge CVE of the Day #033 🚨 CVE-2026-65801 — Microsoft has disclosed a Critical unauthenticated SSRF in Exchange Online. A remote attacker could make a trusted service request cross a security boundary and elevate privileges—no account or victim interaction required. Its maximum CVSS 10.0 reflects Network reachability, Low complexity, No privileges, No interaction, Changed scope and High C/I/A impact. 🔑 Key details: ⭐ Severity: Critical — CVSS 3.1: 10.0 🧠 Weakness: CWE-918 — SSRF 🎯 Target: Microsoft Exchange Online 🔓 Authentication: None 🌐 Attack vector: Network 👆 User interaction: None ⚔️ Impact: Elevation of privilege 🛡️ Fix: Fully mitigated by Microsoft; no customer action 🚫 Exploitation/PoC: None publicly confirmed 📋 CISA KEV: Not listed — checked 25 August 2026 📊 CISA SSVC: None / Automatable / Total impact 📈 EPSS: 0.522% — 41.946th percentile ⚠️ Why it matters: Exchange Online holds sensitive communications and controls mailbox permissions and mail flow. Its unauthenticated, no-click preconditions made the original service flaw exceptionally dangerous. 🛡️ Affected Software & Versions: Microsoft Exchange Online hosted service; no numbered customer version Exchange Server is not listed as affected 🧠 The practical attack surface: The endpoint, parameter, backend target and gained privilege are undisclosed. Mailbox takeover, cross-tenant access, token theft and RCE are not confirmed. Microsoft fully mitigated the hosted flaw before publication. 🔥 CyberForge verdict: A genuine 10.0 cloud flaw—but not an Exchange Server patch alert. No customer fix is required. Preserve Microsoft 365 audit logs and review unexpected mailbox delegates, forwarding, rules, connectors and Exchange role changes. 🔗 Full visual advisory: https://github.com/advisories/GHSA-w5cc-jcwc-q4f8 🔗 Full vulnerability details: https://nvd.nist.gov/vuln/detail/CVE-2026-65801 #CyberSecurity #CVE #ExchangeOnline #SSRF #CloudSecurity #CyberForge

    Post summary

    The advisory announces a critical SSRF vulnerability in Exchange Online, details its technical aspects, and confirms Microsoft has fully mitigated the issue without requiring customer action.

    10020171
    632 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    📨 Microsoft Exchange Online: SSRF flaw lets unauthenticated attackers elevate privileges over a network. CVSS 10 critical. CVE-2026-65801 is patched - verify your tenant is updated. #cybersecurity #ciso #cto #vulnerabilities #msp #mssp https://secalerts.co/vulnerability/CVE-2026-65801?utm_campaign=x https://t.co/zgudMbYEGr

    Post summary

    The post highlights a critical SSRF vulnerability in Microsoft Exchange Online (CVE-2026-65801), stresses its severity, and urges users to confirm that their tenant is patched.

    00010180
    881 followersView on X
  • BT Haberler@BTHaberler
    General

    Microsoft, Entra ID Açığıyla Birlikte Azure Arc, Exchange Online ve Apache Cassandra'da Dört Kritik Açık Daha Kapattı! Daha önce duyurduğumuz Entra ID'deki CVSS 10.0 puanlı uzaktan kod çalıştırma açığı CVE-2026-69836 ile aynı güvenlik döngüsünde, Microsoft'un Azure Arc, Exchange Online ve Apache Cassandra'da dört kritik açık daha kapattığı ortaya çıktı. • Azure Arc'ta CVE-2026-65816 ve CVE-2026-69555 olmak üzere iki ayrı yetkisiz uzaktan yetki yükseltme açığı, Exchange Online'da ise CVE-2026-65801 kodlu benzer bir yetki yükseltme açığı bulunuyor. • Apache Cassandra'daki CVE-2026-65770 ise uzaktan keyfi kod çalıştırılmasına izin veriyor; Microsoft, bu beş açığın hiçbiri için şu ana kadar kamuya açık bir istismar kodu bulunmadığını belirtti. Tek bir güvenlik döngüsünde kimlik yönetimi, hibrit bulut yönetimi, e-posta ve veritabanı katmanlarını aynı anda etkileyen beş kritik açığın ortaya çıkması, Microsoft'un bulut ekosisteminin ne kadar birbirine bağlı ve geniş bir saldırı yüzeyine sahip olduğunu gösteriyor. #SiberGüvenlik #Microsoft #Azure

    Post summary

    Microsoft announced the closure of five critical vulnerabilities across Azure Arc, Exchange Online, and Apache Cassandra, but the article notes no public exploit code or active exploitation, providing only technical details of the CVEs.

    0000046
    39 followersView on X
  • SecureChap@SecureChap
    Patch

    Unauth RCE in Microsoft Entra ID via deserialization of untrusted data. Attackers send crafted objects over the network with no credentials required to gain code execution. CVE-2026-69836 was found by Robert Fitzpatrick and fixed on August 21 2026. An early advisory wrongly flagged active exploitation; Microsoft corrected the record the following day. Three more unauth remote privilege escalations shipped the same day. CVE-2026-65816 and CVE-2026-69555 hit Azure Arc, CVE-2026-65801 affects Exchange Online, and CVE-2026-65770 impacts Azure Managed Instance for Apache Cassandra. Microsoft states no public exploits exist for the August fixes and no customer action is required. CISA added the separate Windows IKE RCE to its actively exploited list on or before the same date.

    Post summary

    Microsoft has fixed CVE‑2026‑69836 and related CVEs, confirms no public exploits or customer action required, and corrects earlier reports of active exploitation.

    00000173
    164 followersView on X
  • ThreatAft@ThreatAft
    Patch

    🚨 CVE-2026-65801 (CVSS 10.0): Critical SSRF in Microsoft Exchange Online. Microsoft has patched server-side. No customer action required. Review security telemetry for suspicious activity. 🔗 https://threataft.com/articles/microsoft-exchange-online-ssrf-privilege-escalation-cve-2026-65801?utm_source=twitter&utm_medium=social&utm_campaign=share #CVE202665801 #Microsoft #ExchangeOnline #SSRF #infosec https://t.co/LJ4LjIuZDk

    Post summary

    Microsoft has issued a patch for the critical SSRF vulnerability in Exchange Online (CVE‑2026‑65801); no customer action is required, but monitoring of security telemetry for suspicious activity is recommended.

    0000038
    37 followersView on X
  • SecureShield@SecureShield_
    General

    一次情報(NVD): https://nvd.nist.gov/vuln/detail/CVE-2026-65801 参照元(ベンダー等): https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65801

    Post summary

    The text provides links to the NVD and Microsoft update guide for CVE-2026-65801 but does not supply technical details, exploitation code, or patch information.

    0000032
    26 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_online---

Explore more