AllCyberNews

CVE-2026-42897

Microsoft Exchange Server Spoofing Vulnerability

CVSS 8.1 high · Microsoft Microsoft Exchange Server 2016 Cumulative Update 23 · published 2026-05-14

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Coverage 2 sources

  1. 2026-05-15 Help Net Security critical Unpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897)

    Microsoft warns of actively exploited XSS vulnerability in on-premises Exchange Server (CVE-2026-42897)

  2. 2026-05-15 CISA Cybersecurity Advisories critical CISA Adds One Known Exploited Vulnerability to Catalog

    CISA adds CVE-2026-42897 to its Known Exploited Vulnerabilities Catalog due to active exploitation.

  3. 2026-07-30 Help Net Security high Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

    Laundry Bear exploits CVE-2026-42897 in Microsoft Exchange via email.

Also covered