What is CVE-2026-42897?
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Timeline
- 2026-05-14Published to the U.S. National Vulnerability Database (NVD)
- 2026-05-15Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-05-16First covered in a defend.network daily briefing
- 2026-05-29CISA federal remediation deadline (BOD 22-01)
- 2026-06-17NVD record last updated
CISA Known Exploited Vulnerability
Microsoft Exchange Server Cross-Site Scripting Vulnerability
Affected product
Microsoft Exchange Server
NVD also lists CPE entries for: Microsoft Exchange Server, Microsoft Exchange Server Subscription Edition
Remediation Steps
- Apply Microsoft security update for Exchange Server immediately from Microsoft Update portal
- Review email security logs for suspicious crafted emails containing XSS payloads dated back 30 days
- Implement enhanced email filtering rules blocking suspicious script content in message headers
- Conduct forensic analysis of user accounts targeted by spoofing attacks
- Enable advanced threat protection features in Exchange Organization configuration
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42897
- https://msrc.microsoft.com/update-guide
- https://learn.microsoft.com/en-us/exchange/security-and-compliance
- https://nvd.nist.gov/vuln/detail/CVE-2026-42897
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 3 of May 2026 (May 18 – 24)
- Microsoft Exchange zero-day in active use; npm worm clones spread after source leak (2026-05-19)
- Zero-days exploited: NGINX, MS Exchange, Cisco SD-WAN; TanStack hit (2026-05-18)
- Critical RCEs exploited: Cisco SD-WAN, Exchange, Funnel Builder (2026-05-17)
- MS Exchange zero-day exploited; npm hits OpenAI; Turla evolves Kazuar (2026-05-16)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.