CVE-2026-42897

Analyzed
Published: 14 May 2026, 17:00
Last modified:15 May 2026, 22:20

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
8.1 HIGH
v3.1 (cve.org)
EPSS Score
0.22% LOW
0% probability
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 May 2026, 17:00
Published
Vulnerability first disclosed
15 May 2026, 00:00
Added to CISA KEV
Microsoft Exchange Server Cross-Site Scripting Vulnerability
15 May 2026, 22:20
Last Modified
Vulnerability information updated
29 May 2026, 00:00
CISA Remediation Due
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:F/RL:O/RC:C
  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 0.22% Percentile: 45%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • UnknownExchange Server

    na | 2016 | 2016:cumulative_update_1 | 2016:cumulative_update_10 | 2016:cumulative_update_11 | 2016:cumulative_update_12 | 2016:cumulative_update_13 | 2016:cumulative_update_14 | 2016:cumulative_update_15 | 2016:cumulative_update_16 | 2016:cumulative_update_17 | 2016:cumulative_update_18 | 2016:cumulative_update_19 | 2016:cumulative_update_2 | 2016:cumulative_update_20 | 2016:cumulative_update_21 | 2016:cumulative_update_22 | 2016:cumulative_update_23 | 2016:cumulative_update_3 | 2016:cumulative_update_4 | 2016:cumulative_update_5 | 2016:cumulative_update_6 | 2016:cumulative_update_7 | 2016:cumulative_update_8 | 2016:cumulative_update_9 | 2019 | 2019:cumulative_update_1 | 2019:cumulative_update_10 | 2019:cumulative_update_11 | 2019:cumulative_update_12 | 2019:cumulative_update_13 | 2019:cumulative_update_14 | 2019:cumulative_update_2 | 2019:cumulative_update_3 | 2019:cumulative_update_4 | 2019:cumulative_update_5 | 2019:cumulative_update_6 | 2019:cumulative_update_7 | 2019:cumulative_update_8 | 2019:cumulative_update_9

  • microsoftmicrosoft exchange server 2016 cumulative update 23

    -

  • microsoftmicrosoft exchange server 2019 cumulative update 14

    -

  • microsoftmicrosoft exchange server 2019 cumulative update 15

    -

  • microsoftmicrosoft exchange server subscription edition rtm

    -

References (2)