Executive brief
Microsoft Exchange Online, the cloud-based email and calendaring service, contains a critical security flaw that allows unauthorized individuals to tamper with data over the internet. An attacker could exploit this to modify sensitive communications or administrative settings without needing any login credentials or user interaction. This poses a severe risk to data integrity and could lead to a total compromise of the organization's email environment.
Technical details
A critical vulnerability (CWE-287) exists in Microsoft Exchange Online due to improper authentication mechanisms. An unauthenticated attacker can exploit this flaw over the network with low complexity and no user interaction required. Successful exploitation allows for unauthorized tampering, potentially leading to full compromise of confidentiality, integrity, and availability (CVSS 10.0). As this is an exclusively hosted service, Microsoft typically manages the deployment of fixes directly within the Exchange Online environment.
Affected products
- Microsoft Exchange Online All versions
Timeline
- 2026-07-24: advisory: NVD publication date