Critical Severity Vulnerability
This vulnerability has been rated as Critical severity. Immediate action is recommended.
CVE-2026-26137
Critical
Low
Medium
High
Critical
9.9
CVSS Score
Vulnerability Description
Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Attack Vector
N
Attack Complexity
L
Privileges Required
L
User Interaction
N
Scope
C
Confidentiality
H
Integrity
H
Availability
L
Known Affected Software
1 configuration(s) from 1 vendor(s)
365_copilot_chat
Version:
-
CPE:
cpe:2.3:a:microsoft:365_copilot_chat:-:*:*:*:*:*:*:*
This vulnerability affects 1 software configuration(s). Ensure you patch all affected systems.
Severity Details
9.9
out of 10.0
Critical
Weakness Type (CWE)
CWE-918
Top 25 #20
Server-Side Request Forgery (SSRF)
- Description
- The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
- Typical Severity
- Medium
- OWASP Top 10
- A10:2021-Server-Side Request Forgery (SSRF)
- Abstraction Level
- Base
Key Information
- Published Date
- March 19, 2026
