CVE-2026-54998
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-54998 is indexed in GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
An attacker can exploit multiple vulnerabilities in Microsoft Exchange to execute arbitrary code, gain elevated permissions, or conduct spoofing attacks.
CSIRTS triage
- What
- Multiple vulnerabilities in Microsoft Exchange can be exploited to execute arbitrary code and gain elevated permissions.
- Who is affected
- All deployments of Microsoft Exchange are affected.
- Urgency
- Remediation is high priority due to the potential for exploitation.
- Action
- Install the latest security patches for Microsoft Exchange.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-54998
Get an email if CVE-2026-54998 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
Exploit availability
Public exploit or proof-of-concept code for CVE-2026-54998 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.
- GitHub PoCPublic proof-of-concept repositories on GitHub reference this CVE.look it up ↗
Advisory coverage (5)
- high[NEW] [high] Microsoft Exchange: Multiple vulnerabilitiescert-bund · 2026-07-15
- unknownNCSC-2026-0234 [1.00] [M/H] Vulnerabilities fixed in Microsoft Exchangencsc-nl · 2026-07-14
- highCVE-2026-54998: Microsoft Exchange Online Elevation of Privilege Vulnerabilitymsrc · 2026-07-14
- high[NEW] [high] Microsoft Exchange Online: Vulnerability allows privilege escalationcert-bund · 2026-07-03
- highCVE-2026-54998: Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate …nvd · 2026-07-02
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-54998)