exchange_online vulnerabilities
CVEs whose affected-version data names the exchange_online package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-65801Critical· 10.0Microsoft Exchange Online Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
▾ MidnightMicrosoft · Microsoft Exchange OnlineEPSS 0.51%via CVEORG
CVE-2026-56191Critical· 10.0Microsoft Exchange Online Tampering Vulnerability
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
▾ MidnightMicrosoft · Microsoft Exchange OnlineEPSS 0.76%via CVEORG
CVE-2026-54998High· 8.8PoCMicrosoft Exchange Online Elevation of Privilege Vulnerability
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
▾ MidnightMicrosoft · Microsoft Exchange OnlineEPSS 0.78%via CVEORG