MEDIUM
CVE-2026-42897
CVSS
6.1
KEV
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Summary dbcve.org
This is a cross-site scripting (XSS) vulnerability in Microsoft Exchange Server where improper input validation allows attackers to inject malicious scripts into web pages generated by the server. The vulnerability enables spoofing attacks over a network, likely through reflected or stored XSS in Exchange's web interfaces.
Mitigation
Apply Microsoft security updates for Exchange Server as they become available; validate and sanitize all user inputs in Exchange web components; consider disabling unnecessary Exchange web services until patched.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
71.77%
Probability of exploitation in next 30 days
99.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.