High severity8.1CISA KEVNVD Advisory· Published May 14, 2026· Updated Jun 17, 2026
CVE-2026-42897
CVE-2026-42897
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
41cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:*+ 39 more
- cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_21:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_4:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_5:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_6:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_7:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_10:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_13:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_14:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:*
- (no CPE)
- cpe:2.3:a:microsoft:exchange_server_subscription_edition:*:*:*:*:*:*:*:*Range: <15.02.2562.043
Patches
Vulnerability mechanics
References
2- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897nvdMitigationVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
28- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026
- 3rd August – Threat Intelligence ReportCheck Point Research · Aug 3, 2026
- Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC releasedHelp Net Security · Aug 2, 2026
- Breach Roundup: OpenAI Models on a Hacking TearGovInfoSecurity · Jul 31, 2026
- Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)Help Net Security · Jul 30, 2026
- Russian spies take their half-click email attack from Zimbra to OutlookThe Register Security · Jul 30, 2026
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential RotationThe Hacker News · Jul 30, 2026
- TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency PatchCyber Security News · Jul 30, 2026
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox accessBleepingComputer · Jul 29, 2026
- Russian-Alligned TA488 Returns With Persistent Outlook Web Access AttackInfosecurity Magazine · Jul 29, 2026
- Laundry Bear’s webmail hackers had more in store after February, report saysThe Record · Jul 29, 2026
- Breach Roundup: CISA Says Agencies Should 'Patch Smarter'GovInfoSecurity · Jun 12, 2026
- Microsoft Patches Exploited Exchange Server VulnerabilitySecurityWeek · Jun 11, 2026
- Microsoft patches Exchange Server zero-day exploited in attacksBleepingComputer · Jun 10, 2026
- Record Microsoft Patch Tuesday, fresh zero-dayHelp Net Security · Jun 10, 2026
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flawsBleepingComputer · Jun 9, 2026
- June 2026 Patch Tuesday forecast: Where are the CVEs?Help Net Security · Jun 5, 2026
- Microsoft Warns of Two Actively Exploited Defender VulnerabilitiesThe Hacker News · May 21, 2026
- Microsoft Exchange Zero-Day Under Attack, No Patch AvailableDark Reading · May 18, 2026
- ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and MoreThe Hacker News · May 18, 2026
- Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploitedHelp Net Security · May 17, 2026
- Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange ServersInfosecurity Magazine · May 15, 2026
- Microsoft Warns of Exchange Server Zero-Day Exploited in the WildSecurityWeek · May 15, 2026
- Unpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897)Help Net Security · May 15, 2026
- Microsoft warns of Exchange zero-day flaw exploited in attacksBleepingComputer · May 15, 2026
- On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted EmailThe Hacker News · May 15, 2026
- Microsoft CVE-2026-42897 Added to CISA KEV Under Active ExploitationVypr Intelligence · May 14, 2026
- CISA Adds One Known Exploited Vulnerability to CatalogCISA Alerts