CVE-2026-55007
Microsoft · Published September 8, 2026
8.1
CVSS v3.1
HIGHPatch availableGet patch
Description
Microsoft Exchange Server Remote Code Execution Vulnerability. Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
Affected Products
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server Subscription Edition RTM
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C