CVE-2026-65801 describes a Server-Side Request Forgery (SSRF) vulnerability in Microsoft Exchange Online. The flaw allows an unauthorized, unauthenticated attacker to elevate privileges over a network by exploiting the SSRF condition. This type of vulnerability can be leveraged to make the server issue requests on behalf of the attacker, potentially accessing internal resources or escalating access rights. The vulnerability is hosted in Microsoft's cloud-based Exchange Online service, broadening its potential impact across enterprise customers. Microsoft has published guidance via the Microsoft Security Response Center (MSRC). The NVD entry is currently in 'Received' status, indicating details may still be pending full analysis. Given the privilege escalation impact and network-based attack vector, this vulnerability is considered high severity.