0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

NCSC-2026-0234: Critical vulnerabilities fixed in Microsoft Exchange on-premises and Online (advisories.ncsc.nl)

· 13d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Five CVEs addressed, including one with CVSS 9.6 (XSS in OWA)
  • Exchange Online patched automatically; no action required
  • On-premises servers require urgent patching, especially with public OWA

"The Dutch NCSC reports on Microsoft-patched vulnerabilities in Exchange Online and Exchange Server. The most critical (CVE-2026-55008, CVSS 9.6) in Outlook Web Access enables cross-site scripting attacks leading to potential data access. Exchange Online is centrally patched; on-premises installations require immediate updates. No active exploitation or proof-of-concept code is known, but Microsoft assesses exploitation as likely in the short term."

Discussion Matrix

0 segments

no comments yet.