CVE-2026-42897
Microsoft Exchange Server Cross-Site Scripting Vulnerability
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Description as published by the source, in English.
Key facts
- Published
- 2026-05-14
- Last modified
- 2026-06-17
- Assigned by
- secure@microsoft.com
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N- Scored by
- nvd@nist.gov (NVD Primary)
- Probability of exploitation
-
70.3 %
higher than 99 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-05-15, with a remediation deadline of 2026-05-29 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Microsoft | Exchange Server | 2016 | Affected |
| Microsoft | Exchange Server | 2019 | Affected |
| Microsoft | Exchange Server Subscription Edition | < 15.02.2562.043 | Affected |
Weakness type
-
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42897
Related at Berigo
Articles
-
Microsoft patches Exchange flaw already exploited in attacks
Mentions this CVE
2026-06-09
CVE-2026-42897 in Exchange Server can be triggered by a crafted email opened in Outlook Web Access, and has been exploited.
-
Exchange vulnerability actively exploited through crafted email in OWA
Mentions this CVE
2026-05-14
CVE-2026-42897 affects on-premises Exchange Server and can execute script in the user's browser session.
-
A fake CAPTCHA gets the user to open a tunnel into the network
Same product
2026-09-01
Microsoft has tracked the TerminalFix campaign, in which compromised websites show a fake Cloudflare CAPTCHA and ask visitors to paste a command into…
-
A Word macro was the way in at defence manufacturers and government bodies
Same product
2026-09-01
Insikt Group has mapped a campaign in which macro-enabled Word documents planted the HOOKEDGE backdoor at defence manufacturers, government bodies an…
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.