MEDIUM

CVE-2026-42897

Microsoft Exchange Server 2026-05-14 CVSS v3.1
CVSS
6.1
KEV

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Summary dbcve.org

This is a cross-site scripting (XSS) vulnerability in Microsoft Exchange Server where improper input validation allows attackers to inject malicious scripts into web pages generated by the server. The vulnerability enables spoofing attacks over a network, likely through reflected or stored XSS in Exchange's web interfaces.

Mitigation

Apply Microsoft security updates for Exchange Server as they become available; validate and sanitize all user inputs in Exchange web components; consider disabling unnecessary Exchange web services until patched.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

71.77%
Probability of exploitation in next 30 days
99.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE