CVE-2026-42897

HIGH KEV

Microsoft Exchange Server Spoofing Vulnerability

Title source: cna
STIX 2.1

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Exploits (1)

nomisec WORKING POC
by atiilla · poc
https://github.com/atiilla/CVE-2026-42897

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory patch
Microsoft Exchange Server Spoofing Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897

Scores

CVSS v3 8.1
EPSS 0.1234
EPSS Percentile 94.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2026-05-15
VulnCheck KEV 2026-05-14
ENISA EUVD EUVD-2026-30343
CWE
CWE-79
Status published
Products (7)
microsoft/exchange_server
microsoft/exchange_server 2016 (24 CPE variants)
microsoft/exchange_server 2019 (15 CPE variants)
Microsoft/Microsoft Exchange Server 2016 Cumulative Update 23 -
Microsoft/Microsoft Exchange Server 2019 Cumulative Update 14 -
Microsoft/Microsoft Exchange Server 2019 Cumulative Update 15 -
Microsoft/Microsoft Exchange Server Subscription Edition RTM -
Published May 14, 2026
KEV Added May 15, 2026
Tracked Since May 14, 2026