CVE-2026-55008 Details
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
A cross-site scripting vulnerability has been identified in Microsoft Exchange Server, specifically in the Subscription Edition RTM, Exchange Server 2019 Cumulative Update 15, Exchange Server 2019 Cumulative Update 14, and Exchange Server 2016 Cumulative Update 23. This vulnerability allows an unauthorized attacker to perform spoofing over the network by improperly neutralizing input during web page generation. Exploitation could involve sending a crafted malicious email to a user, who, upon opening the email in Outlook Web Access, could inadvertently execute arbitrary JavaScript in their browser context.
Microsoft recommends installing the July 2026 Security Updates for the affected version of Exchange Server. For Exchange Server Subscription Edition RTM, the security update is available for download from the Microsoft Exchange Server Subscription Edition RTM Security Update page. For Exchange Server 2019 Cumulative Update 15, the security update can be downloaded from the Microsoft Exchange Server 2019 Cumulative Update 15 Security Update page. Similar instructions apply for Exchange Server 2019 Cumulative Update 14 and Exchange Server 2016 Cumulative Update 23.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft exchange server | 2016 cumulative_update_23 2019 cumulative_update_14 2019 cumulative_update_15 |
CPE
Remediation
| |
| microsoft exchange server subscription edition | < 15.02.2562.045 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |