Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-55008

Опубликовано: 14 июл. 2026
Источник: msrc
CVSS3: 9.6
EPSS Низкий

Описание

Microsoft Exchange Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

FAQ

Microsoft recommends installing the July 2026 Security Updates for your version of Exchange Server to be protected from this vulnerability. Customers who have installed the July 2026 Security Updates on all affected Exchange servers are fully protected and may safely remove the CVE-2026-42897 mitigation (which is similar in nature and mitigates CVE-2026-55008 also). Microsoft recommends keeping the Emergency Mitigation (EM) Service enabled to receive future emergency mitigations and security protections. For additional information, please see the Exchange blog post.

How could an attacker exploit this vulnerability?

An attacker could exploit this issue by sending a specifically crafted malicious email to the user. If the user opens this email, in Outlook Web Access, and certain conditions are met, arbitrary execution of JavaScript would occur in the browser context.

Обновления

ПродуктСтатьяОбновление
Microsoft Exchange Server 2016 Cumulative Update 23
-
Microsoft Exchange Server 2019 Cumulative Update 14
-
Microsoft Exchange Server 2019 Cumulative Update 15
-
Microsoft Exchange Server Subscription Edition RTM

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation More Likely

EPSS

Процентиль: 50%
0.00725
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.6
nvd
19 дней назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 9.6
github
19 дней назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 8.1
msrc
20 дней назад

Microsoft Exchange Server Spoofing Vulnerability

EPSS

Процентиль: 50%
0.00725
Низкий

9.6 Critical

CVSS3