CVE-2026-42897
Microsoft
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVSS
- 6.1
- EPSS
- 70.3% 99.3% percentile
- CISA KEV
- Listed
- Published
- 2026.05.15