Cross-site scripting in Microsoft Exchange Server - CVE-2026-62914
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Exchange Server when rendering web pages. A remote user can inject a specially crafted payload to perform spoofing.
User interaction is required to view the crafted content.