Critical severity10.0NVD Advisory· Published Aug 20, 2026· Updated Aug 24, 2026
CVE-2026-65801
CVE-2026-65801
Description
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
Affected products
1Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65801nvdVendor Advisory
News mentions
4- September 2026 Patch Tuesday forecast: All we need is more timeHelp Net Security · Sep 4, 2026
- ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Hacker News · Aug 24, 2026
- Microsoft Patches Exploited Entra ID VulnerabilitySecurityWeek · Aug 21, 2026
- Microsoft: 25 Vulnerabilities Disclosed, Including Exploited Entra ID FlawVypr Intelligence · Aug 20, 2026