CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability
8.1 KEV Activement exploitée selon la CISA
Analyse sur rafaelpfister.ch
- Article · 19 août 2026 Mises à jour de sécurité Exchange d’août 2026 : faille Pwn2Own corrigée, OWA Light désactivé La SU d’août corrige sept vulnérabilités, dont l’exploit Exchange démontré lors de Pwn2Own 2026, et désactive définitivement OWA Light. Microsoft explique également pourquoi les SU Exchange paraissent désormais chaque mois et pourquoi Exchange SE CU1 se fait toujours attendre.
- Article · 14 juillet 2026 Assurer correctement le suivi des mises à jour de sécurité Exchange de juillet 2026 Après l’installation, deux tâches de nettoyage sont nécessaires : supprimer de manière contrôlée l’ancienne mitigation CVE-2026-42897 et vérifier les groupes hérités sur-privilégiés dans Active Directory.
Description de l'éditeur (en anglais)
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. Données de référence
- Éditeur
- Microsoft
- Produits concernés
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server Subscription Edition RTM
- CVSS 3.1
- 8.1 (HIGH)
- Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:F/RL:O/RC:C- Type de faiblesse
- CWE-79: Cross-Site Scripting
- Publiée
- 14 mai 2026
- Dans le catalogue KEV depuis
- 15 mai 2026
- Échéance administrations fédérales US
- 29 mai 2026