Executive brief
Microsoft Exchange Online is the cloud-based email and collaboration platform used by millions of organizations worldwide. A server-side request forgery vulnerability allows an attacker to elevate their privileges across the network without authorization, potentially compromising email, calendars, and sensitive business communications for affected users.
Technical details
A server-side request forgery (SSRF) vulnerability in Microsoft Exchange Online permits privilege escalation over the network. The vulnerability allows an attacker to forge requests that the Exchange server processes on their behalf, bypassing normal authorization controls. This can be exploited to access restricted resources or perform privileged actions without proper authentication. The attack is network-reachable and does not require prior authentication. Microsoft has released security patches to address this issue.
Affected products
- Microsoft Exchange Online
Timeline
- 2026-08-20: disclosed