← Back

CVE-2026-42897

nvd nist
Published: May 14, 2026Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Affected (40)

2 products
Exchange Server
Configuration A
40 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2016
Version 2016 cumulative_update_10
Version 2016 cumulative_update_11
Version 2016 cumulative_update_12
Version 2016 cumulative_update_13
Version 2016 cumulative_update_14
Version 2016 cumulative_update_15
Version 2016 cumulative_update_16
Version 2016 cumulative_update_17
Version 2016 cumulative_update_18
Version 2016 cumulative_update_19
Version 2016 cumulative_update_1
Version 2016 cumulative_update_20
Version 2016 cumulative_update_21
Version 2016 cumulative_update_22
Version 2016 cumulative_update_23
Version 2016 cumulative_update_2
Version 2016 cumulative_update_3
Version 2016 cumulative_update_4
Version 2016 cumulative_update_5
Version 2016 cumulative_update_6
Version 2016 cumulative_update_7
Version 2016 cumulative_update_8
Version 2016 cumulative_update_9
Version 2019
Version 2019 cumulative_update_10
Version 2019 cumulative_update_11
Version 2019 cumulative_update_12
Version 2019 cumulative_update_13
Version 2019 cumulative_update_14
Version 2019 cumulative_update_1
Version 2019 cumulative_update_2
Version 2019 cumulative_update_3
Version 2019 cumulative_update_4
Version 2019 cumulative_update_5
Version 2019 cumulative_update_6
Version 2019 cumulative_update_7
Version 2019 cumulative_update_8
Version 2019 cumulative_update_9
Before 15.02.2562.043

References (2)

Source: secure@microsoft.com
MitigationVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.