Junglewise Threat Intelligence

CVE-2026-55008: Microsoft Exchange Server cross-site scripting spoofing vulnerability

CVE-2026-55008 · Severity: critical · CVSS 9.6 · Published 2026-07-14

Technologies: Microsoft Exchange Server 2019, Microsoft Exchange Server 2016, Microsoft Exchange Server Subscription Edition. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server, the widely used corporate email and calendaring platform, contains a critical security flaw that allows attackers to perform spoofing attacks. By tricking a user into interacting with a malicious link or page, an attacker can execute unauthorized actions in the context of that user's session. This could lead to the theft of sensitive communications, unauthorized access to mailboxes, or the compromise of user accounts.

Technical details

A critical cross-site scripting (XSS) vulnerability (CWE-79) exists in Microsoft Exchange Server due to improper neutralization of input during web page generation. The vulnerability is reachable over the network and requires minimal user interaction (typically clicking a link) to exploit. Because the vulnerability has a 'Changed' scope (S:C) and high impact on confidentiality, integrity, and availability, it allows an attacker to execute malicious scripts in the victim's browser session. This can lead to session token theft, unauthorized administrative actions, or full account takeover. Affected versions include Exchange Server 2016, 2019, and the Subscription Edition; users should apply the latest cumulative updates from Microsoft.

Affected products

  • Microsoft Exchange Server 2016 Cumulative Update 23 < 15.01.2507.071
  • Microsoft Exchange Server 2019 Cumulative Update 14 < 15.02.1544.043
  • Microsoft Exchange Server 2019 Cumulative Update 15 < 15.02.1748.048
  • Microsoft Exchange Server Subscription Edition RTM < 15.02.2562.045

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats