CVE-2026-42897 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: May 14, 2026
Microsoft Exchange Server - Stored XSS
Published: May 14, 2026Updated: May 14, 2026KEVRemote Exploitable
Overview
Microsoft Exchange Server contains a stored XSS caused by improper neutralization of input during web page generation, letting unauthorized attackers perform spoofing over a network, exploit requires no special privileges.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Unauthorized attackers can perform spoofing attacks over the network, potentially leading to user impersonation or session hijacking.
Mitigation
Update to the latest version of Microsoft Exchange Server.
References
Related Resources
Details
- CVE ID
- CVE-2026-42897
- Severity
- High
- CVSS Score
- 8.1
- Type
- stored_xss
- Status
- unconfirmed
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N