CVE-2026-42897 · CVSS 8.1 HIGH · KEV 2026-05-15 · patch available
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Is CVE-2026-42897 exploited?
Listed in the CISA KEV catalog on 2026-05-15.
Federal remediation due 2026-05-29.
Past that date by 78 days.
Public exploit code: none found in monitored sources.