Cross-site scripting in Microsoft Exchange Server - CVE-2026-69356
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation (cross-site scripting) in Microsoft Exchange Server when processing a specially crafted calendar invitation containing a malicious meeting link. A remote attacker can send a specially crafted calendar invitation to perform spoofing.
User interaction is required to open the meeting and select the Join link.