A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2026-42897

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Published
2026-05-15
Modified
2026-07-31
Sources
cisa-kev

Summary

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.