CVE-2026-42897
Microsoft Exchange Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Coverage 2 sources
-
2026-05-15
Help Net Security
critical
Unpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897)
Microsoft warns of actively exploited XSS vulnerability in on-premises Exchange Server (CVE-2026-42897)
-
2026-05-15
CISA Cybersecurity Advisories
critical
CISA Adds One Known Exploited Vulnerability to Catalog
CISA adds CVE-2026-42897 to its Known Exploited Vulnerabilities Catalog due to active exploitation.
-
2026-07-30
Help Net Security
high
Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
Laundry Bear exploits CVE-2026-42897 in Microsoft Exchange via email.
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands