CVE-2026-55008
This vulnerability is a cross‑site scripting flaw in Microsoft Exchange Server that lets an attacker inject malicious scripts into web pages. The flaw can be exploited without authentication and can cause attackers to spoof the server’s identity. It affects Exchange Server 2016, 2019, and the Subscription Edition.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Microsoft Exchange Server 2016, 2019, and Subscription Edition.
Real-world impact
An attacker could inject malicious scripts that run in the browsers of users who view the compromised pages, allowing them to impersonate the Exchange Server, steal credentials, or perform other malicious actions.
Why this severity
The CVSS score of 9.6 reflects that the vulnerability is exploitable over the network without authentication, requires only user interaction (clicking a link), and can lead to complete compromise of confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 14, 2026 · 20d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- msrc.microsoft.com/update-guide/vulnerability/…vendor advisory