Home / Vulnerabilities / CVE-2026-42897
HIGH SEVERITY
CVE-2026-42897Microsoft · Microsoft

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Technical Severity

CVSS v3.1 Metrics

HIGH
8.1 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploitation Likelihood

EPSS Prediction

6.29 %
Predictive Probability
Percentile Rank
91.0 th

Documented as more likely to be exploited than 91.0% of known CVEs.

Detection Date

May 15, 2026

Remediation Due

May 29, 2026

CISA Catalog Active

Threat Analysis

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

Remediation Directive

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

External Intelligence