SYS::ONLINE
Wasteland.
Briefs1521
Issues20
SinceFeb 2026
LIVE
CVE · Critical CVE-2026-56191 2026-07-23

CVE-2026-56191: Critical Authentication Flaw in Microsoft Exchange Online

"A CVSS 10.0 improper authentication vulnerability in Microsoft Exchange Online lets an unauthenticated attacker tamper with data over the network."

A CVSS 10.0 improper authentication vulnerability in Microsoft Exchange Online lets an unauthenticated attacker tamper with data over the network.

What Is It

CVE-2026-56191 is an improper authentication vulnerability (CWE-287) in Microsoft Exchange Online. According to Microsoft's disclosure, the flaw "allows an unauthorized attacker to perform tampering over a network." It carries a CVSS 3.1 base score of 10.0 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, meaning it is exploitable remotely, requires low attack complexity, needs no privileges and no user interaction, and results in a scope change with high impact to confidentiality, integrity, and availability. The vulnerability was published on 2026-07-23 and is tagged as an exclusively-hosted-service issue.

Why It Matters

A perfect 10.0 score is reserved for the most severe vulnerabilities. Here, an attacker requires no credentials and no victim interaction to reach the flaw across the network. The scope change (S:C) indicates the impact can extend beyond the initially vulnerable component, and all three impact metrics, confidentiality, integrity, and availability, are rated HIGH. Because the description specifically calls out tampering by an unauthorized attacker, the integrity of Exchange Online data is directly at risk.

What's Vulnerable

The affected product is Microsoft Exchange Online (vendor: Microsoft). Microsoft lists the affected version as "-" and flags the CVE as an exclusively-hosted-service, indicating this is a cloud-hosted service rather than on-premises software. No specific affected CPE configurations are enumerated in the NVD record.

Patch Status

As an exclusively-hosted-service vulnerability, remediation is handled by Microsoft on the service side; there is no customer-installed patch enumerated in the supplied data. Refer to Microsoft's MSRC update guide entry for the authoritative status. The NVD record's status is "Received," meaning it is still undergoing analysis.

Sources