Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
References
| Link | Resource |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897 | Mitigation Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42897 | US Government Resource |
Configurations
Configuration 1 (hide)
|
History
15 May 2026, 19:35
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42897 - US Government Resource |
15 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897 - Mitigation, Vendor Advisory |
15 May 2026, 15:20
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_4:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_3:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:-:*:*:*:subscription:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_14:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_5:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_13:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_2:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_7:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_10:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_21:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_6:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:* |
|
| References | () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897 - Vendor Advisory, Mitigation | |
| First Time |
Microsoft
Microsoft exchange Server |
14 May 2026, 18:19
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-14 18:16
Updated : 2026-05-15 19:35
NVD link : CVE-2026-42897
Mitre link : CVE-2026-42897
CVE.ORG link : CVE-2026-42897
JSON object : View
Products Affected
microsoft
- exchange_server
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
