CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability
8.1 KEV Actively exploited according to CISA
Analysis on rafaelpfister.ch
- Article · August 19, 2026 August 2026 Exchange Security Updates: Pwn2Own Vulnerability Fixed, OWA Light Disabled The August SU fixes seven vulnerabilities, including the Exchange exploit demonstrated at Pwn2Own 2026, and permanently disables OWA Light. Microsoft also explains why Exchange SUs are now released monthly and why Exchange SE CU1 is still delayed.
- Article · July 14, 2026 Properly follow up on the July 2026 Exchange security updates Two cleanup tasks are needed after installation: safely remove the old CVE-2026-42897 mitigation and review overprivileged legacy groups in Active Directory.
Vendor description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. Reference data
- Vendor
- Microsoft
- Affected products
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server Subscription Edition RTM
- CVSS 3.1
- 8.1 (HIGH)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:F/RL:O/RC:C- Weakness type
- CWE-79: Cross-Site Scripting
- Published
- May 14, 2026
- In KEV catalog since
- May 15, 2026
- US federal deadline
- May 29, 2026