
🔥 CyberForge CVE of the Day #033 🚨 CVE-2026-65801 — Microsoft has disclosed a Critical unauthenticated SSRF in Exchange Online. A remote attacker could make a trusted service request cross a security boundary and elevate privileges—no account or victim interaction required. Its maximum CVSS 10.0 reflects Network reachability, Low complexity, No privileges, No interaction, Changed scope and High C/I/A impact. 🔑 Key details: ⭐ Severity: Critical — CVSS 3.1: 10.0 🧠 Weakness: CWE-918 — SSRF 🎯 Target: Microsoft Exchange Online 🔓 Authentication: None 🌐 Attack vector: Network 👆 User interaction: None ⚔️ Impact: Elevation of privilege 🛡️ Fix: Fully mitigated by Microsoft; no customer action 🚫 Exploitation/PoC: None publicly confirmed 📋 CISA KEV: Not listed — checked 25 August 2026 📊 CISA SSVC: None / Automatable / Total impact 📈 EPSS: 0.522% — 41.946th percentile ⚠️ Why it matters: Exchange Online holds sensitive communications and controls mailbox permissions and mail flow. Its unauthenticated, no-click preconditions made the original service flaw exceptionally dangerous. 🛡️ Affected Software & Versions: Microsoft Exchange Online hosted service; no numbered customer version Exchange Server is not listed as affected 🧠 The practical attack surface: The endpoint, parameter, backend target and gained privilege are undisclosed. Mailbox takeover, cross-tenant access, token theft and RCE are not confirmed. Microsoft fully mitigated the hosted flaw before publication. 🔥 CyberForge verdict: A genuine 10.0 cloud flaw—but not an Exchange Server patch alert. No customer fix is required. Preserve Microsoft 365 audit logs and review unexpected mailbox delegates, forwarding, rules, connectors and Exchange role changes. 🔗 Full visual advisory: https://github.com/advisories/GHSA-w5cc-jcwc-q4f8 🔗 Full vulnerability details: https://nvd.nist.gov/vuln/detail/CVE-2026-65801 #CyberSecurity #CVE #ExchangeOnline #SSRF #CloudSecurity #CyberForge
Post summary
The advisory announces a critical SSRF vulnerability in Exchange Online, details its technical aspects, and confirms Microsoft has fully mitigated the issue without requiring customer action.





