Stored cross-site scripting in Microsoft Exchange Server - CVE-2026-42897

 

Stored cross-site scripting in Microsoft Exchange Server - CVE-2026-42897

Published: May 15, 2026 / Updated: July 30, 2026


Vulnerability identifier: #VU131560
CSH Severity: High
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-42897
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in Outlook Web Access. A remote attacker can send a specially crafted email message and execute arbitrary JavaScript code in the victim's browser once the email is viewed. 

Note, the vulnerability is being actively exploited in the wild. 


Affected software

Microsoft Exchange Server

How to mitigate CVE-2026-42897

Install update from vendor's website.

Microsoft Exchange Server - addressed in versions 15.01.2507.069, 15.02.1544.041, 15.02.1748.046, 15.02.2562.043

External References

Related Security Bulletins