Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
In plain language
Written by AI from the record
CVE-2026-65801 is a critical Microsoft Exchange Online flaw that could let an attacker gain higher privileges without needing to sign in; most small businesses using Exchange Online should treat it as urgent and ensure Microsoft’s fix/mitigation steps are applied.
CVE-2026-65801 is a Microsoft Exchange Online elevation-of-privilege issue (CWE-918) triggered by a server-side request forgery (SSRF) weakness that can let an unauthorized attacker escalate privileges over a network.
If you're affected
Email system control loss
Mailbox or account compromise
Data theft from Exchange
Service disruption risk
What is it
Think of Microsoft Exchange Online as the “front door” and “control room” for email at your company. This vulnerability could let an attacker trick Exchange Online into making requests on their behalf, and then use that to gain higher permissions—like becoming an administrator—without having to log in themselves.
Who is affected
This matters to you if your business relies on Microsoft Exchange Online for email and mailboxes. Because Exchange Online is cloud-hosted, you can’t fully patch it like an on-prem server; your action is mainly to verify Microsoft’s tenant-side fix/mitigation rollout and ensure your account protections and monitoring are ready.
Reachability gate: this is only a risk if an attacker can reach the vulnerable Exchange Online functionality from the network (no user login is required to attempt the weakness).
How urgent is it
This is a RED (critical) issue because it’s an elevation-of-privilege vulnerability in Microsoft Exchange Online with a weakness that can be triggered remotely. Even though no public exploit code is on record and CISA KEV doesn’t list it, recent press/actor activity signals heightened attention, so you should act now to confirm tenant coverage and apply Microsoft’s remediation steps.
What to do — in detail
What to do (remediation walkthrough)
Confirm scope: Verify your organization uses Microsoft Exchange Online (Microsoft 365 hosted email). If you have any Exchange-related connectivity relying on Exchange Online features, include that in scope.
Follow the steps Microsoft lists for Exchange Online (tenant-side enablement/mitigation and rollout timing if provided).
Confirm coverage for your tenant: Because this is a cloud service, Microsoft’s rollout/coverage matters more than your local patch level. Ask Microsoft support/admin channel to confirm whether your tenant is already covered and, if not, the expected timeframe.
Interim monitoring (until confirmed fixed):
In Microsoft 365 security/admin tooling, watch for suspicious admin activity patterns such as unexpected role/permission changes, unusual mailbox-related actions, and anomalous Exchange Online request patterns.
If your environment has alerting pipelines (e.g., security alerts forwarded to a SOC/central log), ensure they are enabled and that logs remain accessible for follow-up.
Operational verification:
Once Microsoft confirms remediation/rollout, keep monitoring for any lingering suspicious activity for a short window and verify no unexpected privilege changes occurred.
CISA KEV due date
Not available from the provided findings (CISA KEV not listed).
Technical context
Summary
CVE: CVE-2026-65801
Product: Microsoft Exchange Online / exchange online
Weakness: CWE-918 (improper authorization)
Mechanism and trigger
The findings indicate an SSRF (server-side request forgery) weakness in Microsoft Exchange Online that can be used by an unauthorized attacker to elevate privileges over a network. The reported risk profile includes remote attackability with no required user interaction.
Exploitation status
CISA KEV: not listed (per findings).
Public exploit code: none on record (per findings).
Press/actor attention: increased attention tied to UNC6293 (per PULSE).
Fix information
A vendor remediation entry exists via MSRC’s update guide for CVE-2026-65801. Exact fixed version numbers are not present in the provided findings (Exchange Online is cloud-managed).
Prediction vs. action
An EPSS prediction was provided in the findings, but because this issue is treated as RED and the vendor remediation guidance is available, the practical takeaway is to prioritize tenant coverage verification and remediation steps rather than rely on prediction alone.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.