CVE-2026-42897CISA KEV
Microsoft Exchange Server Cross-Site Scripting Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
- Product
- Microsoft
- Added to KEV
- 15 May 2026
- Federal remediation due
- 29 May 2026
- Known ransomware use
- Not reported