🟠 High  |  Source: Microsoft Security Response Center


A vulnerability in Microsoft Exchange Online allows an unauthenticated attacker to tamper with data or functionality over a network due to improper authentication controls. This is a remotely exploitable flaw requiring no user interaction or prior access, making it particularly concerning for organisations relying on Exchange Online for business communications. If exploited, an attacker could manipulate email data, settings, or related services without legitimate credentials.

Security Architect’s Take: Review conditional access policies and network-level controls restricting access to Exchange Online endpoints, and monitor audit logs for anomalous unauthenticated or unexpected modification activity. As this is a SaaS service, mitigation depends on Microsoft deploying a fix — confirm whether your tenant has received the patch and consider enabling enhanced logging via Microsoft Purifier or Defender for Office 365 in the interim.

Original advisory: CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability