CVE-2026-55008
Microsoft Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVSS
- 9.6
- EPSS
- 0.85% 54.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.15