DIRAS TAKE
Urgent: public exploit code exists for CVE-2026-54998, which raises immediate risk to internet-exposed Exchange Online tenants and warrants rapid mitigation or patching per vendor guidance.
What is CVE-2026-54998?
An authorized attacker can elevate privileges on Microsoft Exchange Online, potentially gaining broader access to mailboxes and administrative functions. This is tracked as CVE-2026-54998. Microsoft Exchange Online is listed as affected; the vendor description indicates an incorrect authorization check. The vulnerability requires a network-capable actor with an authorized account and does not require user interaction, according to available information.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Microsoft Exchange Online are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Microsoft Exchange Online | - |
Is CVE-2026-54998 being exploited?
Public exploit code is available for CVE-2026-54998.
How to fix CVE-2026-54998
- Apply Microsoft’s official updates or mitigations immediately when published and follow vendor guidance for Exchange Online.
- Restrict administrative and privileged account access and enforce least privilege for Exchange Online roles.
- Monitor Exchange Online audit logs and privileged account activity for unusual access or escalation attempts.
- Limit network exposure of management interfaces and require multi-factor authentication for accounts with elevated privileges.
Frequently asked questions
Is CVE-2026-54998 being actively exploited?
Public exploit code for CVE-2026-54998 is available, increasing the risk of active exploitation against Microsoft Exchange Online.
Which Microsoft Exchange Online versions are affected by CVE-2026-54998?
Microsoft Exchange Online is listed as affected; the vendor description does not specify individual version numbers or builds.
Is there a patch for CVE-2026-54998?
A patch is available according to the facts provided; follow Microsoft’s published guidance for Exchange Online to apply fixes or mitigations.
Does CVE-2026-54998 require authentication?
Yes. The vulnerability requires an authorized attacker account to exploit authorization weaknesses in Microsoft Exchange Online.
References
- nvd.nist.gov/vuln/detail/CVE-2026-54998
- cve.org/CVERecord?id=CVE-2026-54998
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54998
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026