LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-42897

CVE-2026-42897 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: May 14, 2026

Microsoft Exchange Server - Stored XSS

Published: May 14, 2026Updated: May 14, 2026KEVRemote Exploitable

Overview

Microsoft Exchange Server contains a stored XSS caused by improper neutralization of input during web page generation, letting unauthorized attackers perform spoofing over a network, exploit requires no special privileges.

Severity & Score

Severity: High
CVSS Score: 8.1

Impact

Unauthorized attackers can perform spoofing attacks over the network, potentially leading to user impersonation or session hijacking.

Mitigation

Update to the latest version of Microsoft Exchange Server.

Details

CVE ID
CVE-2026-42897
Severity
High
CVSS Score
8.1
Type
stored_xss
Status
unconfirmed

CWE

  • CWE-79

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N