NCSC-2026-0234 [1.00] [M/H] Vulnerabilities fixed in Microsoft Exchange
Microsoft has fixed vulnerabilities in Exchange, both Online and on-premise. An attacker can exploit the vulnerabilities to impersonate other users, grant themselves elevated privileges, potentially execute arbitrary code, and gain access to sensitive data. The vulnerability in Exchange Online has now been centrally fixed by Microsoft and is included for information. No actions are required for this. The most severe vulnerability in Exchange Server (on-premise) has been assigned a CVSS of 9.6 and is located in Outlook Web Access. This vulnerability allows an attacker to perform a Cross-Site Scripting (XSS) attack and gain access to the victim's environment. No active exploitation has been observed yet, and there is also no Proof-of-Concept code (PoC) known, but Microsoft indicates that they consider the likelihood of exploitation in the short term to be probable. In particular, OWA environments that are publicly accessible are at increased risk.
CSIRTS triage
- What
- Vulnerabilities allow an attacker to impersonate users, grant elevated privileges, and potentially execute arbitrary code.
- Who is affected
- Users of Microsoft Exchange, both Online and on-premise.
- Urgency
- Remediation is urgent due to the potential for exploitation, especially in on-premise environments.
- Action
- Apply the latest security updates provided by Microsoft for Exchange.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Exchange
Get an email when a new Exchange advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0234
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-549980.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all scored CVEs.
- Low exploitation riskCVE-2026-550050.66% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all scored CVEs.
- Low exploitation riskCVE-2026-550060.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-550080.85% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all scored CVEs.
- Moderate exploitation riskCVE-2026-550091.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 74% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-54998 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55005 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55006 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55008 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55009 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Microsoft Exchange: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Microsoft products (July 15, 2026)cert-fr-avis
- highCVE-2026-55009: Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker t…nvd
- criticalCVE-2026-55008: Improper neutralization of input during web page generation ('cross-site scripting') in Micros…nvd
- highCVE-2026-55006: Insufficient granularity of access control in Microsoft Exchange Server allows an authorized a…nvd
- highCVE-2026-55005: Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execu…nvd
- highCVE-2026-54998: Microsoft Exchange Online Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-55006: Microsoft Exchange Server Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-55005: Microsoft Exchange Server Remote Code Execution Vulnerabilitymsrc
- criticalCVE-2026-55008: Microsoft Exchange Server Spoofing Vulnerabilitymsrc
- highCVE-2026-55009: Microsoft Exchange Server Elevation of Privilege Vulnerabilitymsrc
- high[NEW] [high] Microsoft Exchange Online: Vulnerability allows privilege escalationcert-bund
Recent advisories for Microsoft Exchange
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Microsoft Azure, Copilot, Exchange, Surface: Multiple vulnerabilitiescert-bund · 2026-07-27
- criticalCVE-2026-56191: Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perfor…nvd · 2026-07-24
- high[NEW] [high] Microsoft Exchange: Multiple vulnerabilitiescert-bund · 2026-07-15
- highCVE-2026-55009: Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker t…nvd · 2026-07-14
- criticalCVE-2026-55008: Improper neutralization of input during web page generation ('cross-site scripting') in Micros…nvd · 2026-07-14
- highCVE-2026-55006: Insufficient granularity of access control in Microsoft Exchange Server allows an authorized a…nvd · 2026-07-14
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30