Overview
What is CVE-2026-42897?
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Microsoft Exchange Server Cross-Site Scripting Vulnerability
CISA lists CVE-2026-42897 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Microsoft Microsoft.
Public exploit: Not collected. Review the linked vendor advisory and apply the mitigation or fixed release for your affected product.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.