Skip to content
Microsoft Exchange 'Ghost-Sender' Flaw Enables Widespread Email Spoofing

Microsoft Exchange 'Ghost-Sender' Flaw Enables Widespread Email Spoofing

First seen 9 Jun 2026, 23:41 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 10, 2026 at 23:26 UTC
  • The 'Ghost-Sender' flaw allows email spoofing from any address in Microsoft Exchange environments.
  • Less than 50% of organizations with vulnerable configurations have applied mitigations.
  • Mitigations involve setting up connectors or mail flow rules to prevent spoofing.

A newly identified vulnerability in Microsoft Exchange, termed 'Ghost-Sender', allows attackers to spoof any email address, bypassing standard email authentication controls. This flaw affects organizations using Exchange Online or hybrid configurations with third-party mail servers, enabling forged messages to be delivered directly to users' inboxes. Swiss cybersecurity firm InfoGuard reported that this misconfiguration is widespread, with fewer than half of affected organizations applying mitigations. Attackers can impersonate internal and external email addresses, raising the risk of phishing and fraud. Microsoft has acknowledged the issue, with indications that it is being actively exploited. Mitigations include setting up partner organization connectors or creating specific mail flow rules. InfoGuard has also developed a testing tool to help organizations identify vulnerabilities in their configurations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 102d ago How this analysis works

Timeline

2026-06-09
Ghost-Sender vulnerability disclosed
InfoGuard published research revealing a flaw in Microsoft Exchange that allows email spoofing, affecting hybrid and cloud deployments.
Darkreading
2026-06-09
Active exploitation reported
Microsoft support indicated that the Ghost-Sender issue or a related vulnerability is being actively exploited in the wild.
Darkreading
2026-06-09
Mitigation recommendations provided
Organizations are advised to implement partner organization connectors or mail flow rules to mitigate the spoofing risk.
Gbhackers

More articles in this cluster (2)