Sale of a 0‑day exploit for accessing Microsoft 365 infrastructure
Dark Web2026-07-02, 09:39
For informational purposes only
Vulnerability type: SSRF
According to the author, the Microsoft 365 0‑click pre‑auth exploit enables bypassing Exchange Online's network isolation and gaining access to internal infrastructure through protocol desynchronization. The post includes technical fragments of HTTP responses as alleged proof and claims capabilities for session hijacking, evading protective mechanisms, and potentially mass account takeover. It also notes that cache poisoning does not work in this attack.
Price:
- $1M (starting bid)
- $2.5M (buy‑it‑now)
Vendors
Products