NCSC-2026-0234: Critical vulnerabilities fixed in Microsoft Exchange on-premises and Online (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Five CVEs addressed, including one with CVSS 9.6 (XSS in OWA)
- Exchange Online patched automatically; no action required
- On-premises servers require urgent patching, especially with public OWA
"The Dutch NCSC reports on Microsoft-patched vulnerabilities in Exchange Online and Exchange Server. The most critical (CVE-2026-55008, CVSS 9.6) in Outlook Web Access enables cross-site scripting attacks leading to potential data access. Exchange Online is centrally patched; on-premises installations require immediate updates. No active exploitation or proof-of-concept code is known, but Microsoft assesses exploitation as likely in the short term."
no comments yet.