CVE-2026-42897
Microsoft Exchange Server Cross-Site Scripting Vulnerability - [Actively Exploited]
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
INFO
Published Date :
May 14, 2026, 6:16 p.m.
Last Modified :
June 17, 2026, 10:48 a.m.
Remotely Exploit :
No
Source :
[email protected]
CISA KEV (Known Exploited Vulnerabilities)
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.
Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Unknown
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897 ; https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service ; https://nvd.nist.gov/vuln/detail/CVE-2026-42897
Affected Products
The following products are affected by CVE-2026-42897
vulnerability.
Even if cvefeed.io is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | HIGH | f38d906d-7342-40ea-92c1-6c4a2c6478c8 | ||||
| CVSS 3.1 | HIGH | [email protected] | ||||
| CVSS 3.1 | MEDIUM | [email protected] |
Public PoC/Exploit Available at Github
CVE-2026-42897 has a 9 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-42897.
| URL | Resource |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897 | Mitigation Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42897 | US Government Resource |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-42897 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-42897
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Alle Inhalte von rafaelpfister.ch als Markdown mit strukturierten Metadaten.
Artikel und Inhalte von rafaelpfister.ch als Markdown – E-Mail-Verschlüsselung, SEPPmail/totemomail, HIN Mailgateway, Microsoft 365.
JavaScript Astro TypeScript CSS
주요 CVE 분석
None
Jupyter Notebook Python
None
PowerShell Batchfile HTML
None
TypeScript Batchfile JavaScript Dockerfile HTML CSS Shell PowerShell Go PLpgSQL
CVE-2026-42897 - Exchange Health Checker blind spot: outbound IIS URL Rewrite rules silently ignored, making EOMT mitigations invisible in diagnostic reports.
PowerShell
None
ai-agent cve cybersecurity epss kev llm mitre-attack nvd soc threat-intelligence vulnerability vulnerability-scanner
Python Batchfile HTML Dockerfile Shell
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
security cve exploit poc vulnerability
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-42897 vulnerability anywhere in the article.
-
Ars Technica
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from the ... Read more
-
security.nl
'Europese overheidsinstanties doelwit van Outlook Web Access XSS-aanval'
Europese overheidsinstanties zijn vorige week het doelwit geweest van een aanval waarbij misbruik werd gemaakt van een cross-site scripting (XSS)-lek in Outlook Web Access (OWA). Het doel van de aanva ... Read more
-
The Hacker News
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (O ... Read more
-
Proofpoint
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
July 29, 2026 By Greg Lesnewich, Stuart Del Caliz, Nick Attfield, Konstantin Klinger, Saher Naumaan, Mark Kelly, and the Proofpoint Threat Research Team Threat Research would like to thank the Proofpo ... Read more
-
europa.eu
Cyber Brief 26-07 - June 2026
Cyber Brief (June 2026)July 1, 2026 - Version: 1TLP:CLEARExecutive summaryWe analysed 366 open source reports for this Cyber Brief.1Relating to cyber policy and law enforcement, the Council of the Eur ... Read more
-
security.nl
Microsoft komt met update voor actief aangevallen XSS-lek in Exchange Server
Microsoft heeft een beveiligingsupdate uitgebracht voor een actief aangevallen cross-site scripting (XSS) lek in Exchange Server en roept organisaties en beheerders op om de patch zo snel mogelijk te ... Read more
-
Proofpoint
More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild
Executive Summary The CVE Landscape Has Changed. The Threat Actors Haven't. Proofpoint's dual telemetry streams — targeted attack visibility covering hundreds of millions of messages daily, and a glob ... Read more
-
The Hacker News
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the ... Read more
-
The Hacker News
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to ... Read more
-
The Hacker News
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based o ... Read more
-
The Hacker News
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, ... Read more
-
The Hacker News
Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CV ... Read more
-
The Hacker News
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild. The former, tracked as CVE-2026-41091, is rated 7.8 on the ... Read more
-
The Hacker News
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a ca ... Read more
-
The Hacker News
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
Drupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or infor ... Read more
-
The Hacker News
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked as CVE-2026-45585, carries a C ... Read more
-
The Hacker News
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enabl ... Read more
-
TheCyberThrone
Pwn2Own Berlin 2026 a Detailed Report
The curtain has fallen on Pwn2Own Berlin 2026. Three days. 47 unique zero-day vulnerabilities. $1,298,250 in total payouts. And a competition that, for the first time in its 19-year history, ran out o ... Read more
-
CybersecurityNews
CISA Warns of Microsoft Exchange Server Vulnerability Exploited in Attacks
CISA has issued a fresh warning about a newly disclosed Microsoft Exchange Server vulnerability that is already being exploited in real-world attacks, raising concerns for organizations relying on on- ... Read more
-
The Hacker News
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw ... Read more
The following table lists the changes that have been made to the
CVE-2026-42897 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'Microsoft', 'product': 'Microsoft Exchange Server 2016 Cumulative Update 23', 'versions': [{'status': 'affected', 'version': '15.01.0.0', 'lessThan': '15.01.2507.069', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Microsoft Exchange Server 2019 Cumulative Update 14', 'versions': [{'status': 'affected', 'version': '15.02.0.0', 'lessThan': '15.02.1544.041', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Microsoft Exchange Server 2019 Cumulative Update 15', 'versions': [{'status': 'affected', 'version': '15.02.0.0', 'lessThan': '15.02.1748.046', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Microsoft Exchange Server Subscription Edition RTM', 'versions': [{'status': 'affected', 'version': '15.02.0.0', 'lessThan': '15.02.2562.043', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-42897', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-14T00:00:00+00:00'} -
Modified Analysis by [email protected]
Jun. 15, 2026
Action Type Old Value New Value Changed CPE Configuration OR *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_6:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_5:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_2:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_7:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_3:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_4:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_21:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_10:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_13:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_14:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:-:*:*:*:subscription:*:*:* OR *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_6:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_5:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_2:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_7:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_3:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_4:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_21:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_10:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_13:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_14:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server_subscription_edition:*:*:*:*:*:*:*:* versions up to (excluding) 15.02.2562.043 -
Modified Analysis by [email protected]
May. 15, 2026
Action Type Old Value New Value Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42897 Types: US Government Resource -
CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725
May. 15, 2026
Action Type Old Value New Value Added Date Added 2026-05-15 Added Due Date 2026-05-15 Added Required Action 2026-05-15 Added Vulnerability Name 2026-05-15 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
May. 15, 2026
Action Type Old Value New Value Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42897 -
Initial Analysis by [email protected]
May. 15, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Added CPE Configuration OR *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_6:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_5:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_2:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_7:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_3:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_4:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_21:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_10:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_13:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_14:*:*:*:*:*:* *cpe:2.3:a:microsoft:exchange_server:-:*:*:*:subscription:*:*:* Added Reference Type Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897 Types: Mitigation, Vendor Advisory -
New CVE Received by [email protected]
May. 14, 2026
Action Type Old Value New Value Added Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N Added CWE CWE-79 Added Reference https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897