Record summary

CVE-2026-65813 has a selected CVSS score of 6.5 (medium).

Description

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Microsoft Exchange Server 2016 Cumulative Update 23

Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 23
CVE List15.01.0.0 to < 15.01.2507.072affected

Microsoft Exchange Server 2019 Cumulative Update 14

Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 14
CVE List15.02.0.0 to < 15.02.1544.044affected

Microsoft Exchange Server 2019 Cumulative Update 15

Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 15
CVE List15.02.0.0 to < 15.02.1748.049affected

Microsoft Exchange Server Subscription Edition RTM

Browse Microsoft / Microsoft Exchange Server Subscription Edition RTM
CVE List15.02.0.0 to < 15.02.2562.046affected

References

2