CVE-2026-55009
Microsoft Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
- CVSS
- 7.8
- EPSS
- 1.61% 73.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.15