← Back to browse · API

CVE-2026-42897

Severity
HIGH
CVSS
8.1
EPSS
0.70307
Risk score
82.01
CISA KEV
Yes
PoC
No
Published
2026-05-14
Modified
2026-06-19
First seen
2026-08-07
Aliases
EUVD-2026-30343, GHSA-3C39-338M-M4VP
Products
Microsoft:Microsoft, Microsoft:Microsoft Exchange Server 2016 Cumulative Update 23 15.01.0.0 <15.01.2507.069, Microsoft:Microsoft Exchange Server 2019 Cumulative Update 14 15.02.0.0 <15.02.1544.041, Microsoft:Microsoft Exchange Server 2019 Cumulative Update 15 15.02.0.0 <15.02.1748.046, Microsoft:Microsoft Exchange Server Subscription Edition RTM 15.02.0.0 <15.02.2562.043
Sources
cisa.gov CVE-2026-42897
euvd EUVD-2026-30343

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

References