Sploitus

CVE-2026-42897

1 known exploit for CVE-2026-42897

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Affected products
Exchange Server
Microsoft Exchange Server
= 2016, 2019
Microsoft Exchange Server Subscription Edition
< 15.02.2562.043
Fix
Available
CVSS 3.1
8.1 HIGH
EPSS
5.6% (92th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2026-05-14
CVE-2026-42897 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-42897

Proof-of-concept code and exploit modules indexed by Sploitus