Microsoft disclosed CVE-2026-56191, a critical improper authentication vulnerability in Exchange Online that allowed unauthenticated remote attackers to perform tampering against the hosted service. The flaw, tracked under CWE-287, carries a CVSS 3.1 score of 10.0 with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating potential impact across confidentiality, integrity, and availability in affected tenants.
According to published advisories, the issue could have enabled unauthorized changes to Exchange Online data or configuration, including mail flow rules, mailbox permissions, compliance settings, and audit configurations. Microsoft said the vulnerability affected Exchange Online only, not on-premises Exchange Server, and remediated it through a backend service update. At the time of publication, no active exploitation had been reported, but organizations were urged to review tenant configurations, privileged roles, forwarding and inbox rules, and audit logs for signs of unauthorized modification.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
As of the referenced publication, no active exploitation of CVE-2026-56191 had been reported. This was stated alongside guidance for defenders to review Exchange Online tenant settings and logs for unauthorized changes.
CVE-2026-56191 was publicly listed as a newly received vulnerability affecting Microsoft Exchange Online, with sources describing it as an improper authentication flaw enabling unauthorized tampering over a network. Public reporting assigned it critical severity, including a CVSS 3.1 score of 10.0 in one reference.
Microsoft addressed CVE-2026-56191 in Exchange Online through a backend service update documented in the Microsoft Security Update Guide. The flaw is an improper authentication issue that could allow unauthenticated network attackers to tamper with Exchange Online data or configuration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.