HIGHVulnerability
Verified
Global

CISA KEV: Microsoft Microsoft — Microsoft Exchange Server Cross-Site Scripting Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

Analysis

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context. Added to CISA Known Exploited Vulnerabilities catalog on 2026-05-15. Remediation due: 2026-05-29.

Indicators of Compromise (1)

CVE (1)
CVE-2026-42897
Source Attribution

Originally published by CISA KEV on May 15, 2026. Verified by: CISA.

Related Threats