Back threataft.com Threataft Blog News Aug 21, 2026 CVE-2026-65801: Microsoft Exchange Online SSRF - CVSS 10 threataft.com Open source
What happened: A critical server-side request forgery (SSRF) vulnerability ( CVE-2026-65801 , CVSS 10.0) was discovered in Microsoft Exchange Online. The published vulnerability description states that an unauthenticated attacker can exploit the SSRF condition to achieve unauthorized privilege escalation over a network [citation:6][citation:9]. Attack vector: An attacker may attempt to induce server-side requests to unintended destinations. The precise reachable resources and downstream impact should not be inferred beyond the behavior documented by Microsoft and the CVE record. Impact: Privilege escalation — the confirmed published impact is unauthorized privilege escalation over the network [citation:6][citation:9]. Broader SSRF consequences should be treated as potential rather than confirmed CVE-specific behavior. Affected products: Microsoft Exchange Online (cloud-hosted service only — no on-premises Exchange Server versions affected) [citation:6][citation:8]. Patch status: No customer action required. Microsoft has already deployed server-side mitigations for the cloud service. The vulnerability does not require customer action to resolve [citation:9][citation:12]. Defender actions: No immediate patching required. Review Microsoft-provided security guidance and available tenant-level telemetry for suspicious activity. Do not assume that tenant logs expose every server-side request generated within Exchange Online. Exploitation status: No active exploitation or public proof-of-concept was identified in the sources reviewed for this article as of August 21, 2026. CISA KEV Status: Not identified in the sources reviewed as of August 21, 2026.
📋 Status Summary: ✔ Publicly disclosed — August 20, 2026 [citation:6][citation:9] ✔ CVSS 10.0 — Critical severity [citation:6][citation:9] ✔ Vulnerability Type — CWE-918: Server-Side Request Forgery (SSRF) [citation:6][citation:9] ✔ Cloud service only — No on-premises Exchange Server versions affected [citation:6][citation:8] ✔ No customer action required — Microsoft has deployed server-side mitigations [citation:9][citation:12] ✘ Public exploit confirmed — Not yet [citation:8] ✘ CISA KEV listing — Not identified in the sources reviewed as of August 21, 2026
⚠️ Critical Note: This is an Exchange Online cloud-service vulnerability. Microsoft has already deployed server-side mitigations for the cloud service, and no customer action is required to address this specific vulnerability [citation:9][citation:12]. On-premises Exchange Server deployments are not affected [citation:6][citation:8].
A critical server-side request forgery (SSRF) vulnerability in Microsoft Exchange Online, tracked as CVE-2026-65801 , carries a maximum CVSS v3.1 base score of 10.0 (Critical) [citation:6][citation:9]. The flaw allows an unauthenticated remote attacker to elevate privileges over a network by exploiting insufficient validation of server-side requests [citation:6][citation:7].
The vulnerability exists in the cloud-hosted Microsoft Exchange Online service and does not affect on-premises Exchange Server deployments [citation:6][citation:8]. Microsoft has already deployed server-side mitigations for the cloud service, and no customer action is required to remediate the vulnerability [citation:9][citation:12].
The SSRF condition can cause a vulnerable server-side component to make requests to destinations that an external attacker may not be able to reach directly. For CVE-2026-65801 , the documented impact is unauthorized privilege escalation over a network [citation:6][citation:9].
While no active exploitation or public proof-of-concept was identified in the sources reviewed for this article as of August 21, 2026, the CVSS 10.0 rating reflects the severity of the published vulnerability characteristics, not evidence that exploitation is occurring. Organizations should review their monitoring for anomalous outbound requests from Exchange Online and audit privileged activity for signs of post-exploitation behavior [citation:8].
Exchange Online is a core component of Microsoft 365, used by millions of organizations worldwide for email, calendaring, and collaboration services. An SSRF vulnerability in this service that allows unauthenticated privilege escalation represents a severe risk to cloud infrastructure.
The vulnerability allows an attacker with no credentials or user interaction to make the Exchange Online server issue requests to internal resources [citation:7]. This could include:
While Microsoft has already deployed server-side mitigations, the vulnerability's maximum CVSS score of 10.0 reflects the potential impact: unauthenticated remote exploitation, low attack complexity, and full compromise of confidentiality, integrity, and availability with changed scope [citation:6][citation:9].
CVE-2026-65801 is classified as CWE-918 — Server-Side Request Forgery (SSRF) [citation:6][citation:9]. This vulnerability occurs when a web server receives a URL or similar request from an upstream component and retrieves the contents of that URL, but does not sufficiently ensure that the request is being sent to the expected destination [citation:7].
In an SSRF vulnerability, the application makes a request to a URL that is partially or fully controlled by the user [citation:7]. This allows an attacker to:
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H [citation:6][citation:9]
The following is a conceptual flow based on the published SSRF classification and privilege-escalation impact. It is not intended to represent a confirmed exploit chain or to imply access to specific internal endpoints.
Exchange Online is a Microsoft-managed cloud service. Customers do not install an Exchange Server security update for this vulnerability. Follow Microsoft's current security advisory and Microsoft 365 Service Health guidance for the latest remediation status and any customer-specific actions.
The following mapping describes how exploitation and potential downstream activity may align with ATT&CK. It should be treated as an analytical mapping rather than an official ATT&CK classification of the CVE.
CVE-2026-65801 is a critical server-side request forgery (SSRF) vulnerability (CVSS 10.0) in Microsoft Exchange Online that allows an unauthenticated remote attacker to elevate privileges over a network [citation:6][citation:9].
The CVSS v3.1 base score is 10.0 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H [citation:6][citation:9].
Microsoft Exchange Online — the cloud-hosted service. No on-premises Exchange Server versions are affected [citation:6][citation:8].
No customer action is required. Microsoft has already deployed server-side mitigations for Exchange Online [citation:9][citation:12].
No active exploitation or public proof-of-concept was identified in the sources reviewed for this article as of August 21, 2026. This status can change as new research becomes available.
No. This vulnerability affects only Microsoft Exchange Online, the cloud-hosted service [citation:6][citation:8].
Customers do not install an Exchange Server patch for this cloud-service issue. Organizations should follow Microsoft's current advisory and review available security and audit telemetry for suspicious activity.
CVE-2026-65801 is a critical server-side request forgery (SSRF) vulnerability in Microsoft Exchange Online. The published vulnerability description identifies unauthorized privilege escalation over a network as the impact, with a CVSS v3.1 base score of 10.0 [citation:6][citation:9].
Because Exchange Online is a Microsoft-managed cloud service, customers do not install an Exchange Server security update for this issue. Organizations should follow Microsoft's current advisory and Microsoft 365 Service Health guidance for remediation status and any tenant-specific actions.
Security teams should also review available Microsoft security and audit telemetry for suspicious authentication, authorization, or administrative activity. Tenant-level logging should not be assumed to expose every server-side request generated within Exchange Online.
Here's what you should do now:
Bottom line: no Exchange Server patch is installed by the customer for this cloud-service vulnerability. Follow Microsoft guidance and review available security telemetry.
— The ThreatAft Security Team
Written by: ThreatAft Security Team – Vulnerability research, enterprise security, and threat intelligence.
Last reviewed: August 21, 2026. Vulnerability details and affected products are based on the referenced CVE record and Microsoft security information available at the time of review. Exploitation status and threat intelligence can change; organizations should consult Microsoft's official advisory for the latest information.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
