Junglewise Threat Intelligence

CVE-2026-65813: Microsoft Exchange Server SSRF privilege escalation

CVE-2026-65813 · Severity: medium · CVSS 6.5 · Published 2026-08-11

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server is a widely-deployed email and collaboration platform used by enterprises to manage corporate communications. A server-side request forgery vulnerability allows an authorized attacker to make the server perform unintended requests, which could be leveraged to escalate privileges within the network. This could lead to unauthorized access to sensitive email data and system resources.

Technical details

This vulnerability is a server-side request forgery (SSRF) in Microsoft Exchange Server that requires an authorized attacker to be present on the network. An authenticated attacker can exploit this flaw to make the Exchange server send requests to internal resources or services, potentially bypassing access controls and escalating privileges. The attack vector is network-based and requires valid credentials. A patch is expected to be available through Microsoft's security update process.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2026-08-11: disclosed

References

Related threats