A critical server-side request forgery (SSRF) vulnerability, designated CVE-2026-65801, has been identified in Microsoft Exchange Online. This vulnerability enables an unauthorized attacker to forge requests from the server to internal systems, potentially allowing privilege escalation over a network. The CVSS score of 10.0 indicates the highest severity level, posing a critical risk to affected organizations. All versions of Microsoft Exchange Online are impacted, making this a widespread concern. Attackers could exploit this vulnerability to bypass security controls and gain unauthorized access to sensitive resources. The risk is particularly high for organizations relying on the platform for email and collaboration services. Immediate action is required to mitigate this threat. Users are strongly advised to apply the latest security patches provided by the vendor. Additionally, network segmentation and strict access controls should be enforced to limit potential exploitation. Organizations should monitor for any suspicious activity and ensure that all systems are up to date with the most recent security updates. Failure to address this vulnerability could result in severe security breaches and data exposure.
CRITICAL
CVSS 10.0
CVE-2026-65801
2026-08-21
Critical SSRF Vulnerability in Microsoft Exchange Online (CVE-2026-65801)
A critical server-side request forgery (SSRF) vulnerability in Microsoft Exchange Online allows unauthorized attackers to elevate privileges over a network. This affects all versions of the platform and requires immediate mitigation.