CVE-2026-55006
Microsoft · Published July 14, 2026
7.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Microsoft Exchange Server Elevation of Privilege Vulnerability. Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Affected Products
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server Subscription Edition RTM
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C