Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5065 articles · 189456 vulns · 37/41 feeds (7d)
← Back to list
8.1
CVE-2026-42897KEVEXPLOITEDPATCHED
microsoft · exchange_server

Microsoft Exchange Server Spoofing Vulnerability

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Affected Products

VendorProductVersions
microsoftexchange_server15.01.0.0, 15.02.0.0, 15.02.0.0, 15.02.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftmicrosoft exchange server 2019 cumulative updatemitre_affected90%
microsoftmicrosoft exchange server subscription edition rtmmitre_affected90%
microsoftexchangecert_advisory90%
microsoftexchange_server_subscription_editioncve_cpe95%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897(vendor-advisory, patch)

Related News (30 articles)

Tier B
JPCERT/CC
Security Alert: Microsoft Releases June 2026 Security Updates
→ No new info (linked only)
Tier D
The Hacker News10d ago
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
→ No new info (linked only)
Tier D
Help Net Security11d ago
Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released
→ No new info (linked only)
Tier D
Heise Security13d ago
Russische Akteure greifen über Outlook-Web-Access-Lücke an
→ No new info (linked only)
Tier D
Help Net Security14d ago
Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
→ No new info (linked only)
Tier D
CSO Online14d ago
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
→ No new info (linked only)
Tier D
BleepingComputer14d ago
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
→ No new info (linked only)
Tier D
Infosecurity Magazine15d ago
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
→ No new info (linked only)
Tier D
The Record15d ago
Laundry Bear’s webmail hackers had more in store after February, report says
→ No new info (linked only)
Tier D
SecurityWeek63d ago
Microsoft Patches Exploited Exchange Server Vulnerability
→ No new info (linked only)
Tier D
CSO Online64d ago
June Patch Tuesday marks a ‘new normal’ with over 200 CVEs, 32 rated ‘critical’
→ No new info (linked only)
Tier D
BleepingComputer64d ago
Microsoft patches Exchange Server zero-day exploited in attacks
→ No new info (linked only)
Tier D
BleepingComputer64d ago
Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws
→ No new info (linked only)
Tier D
Dark Reading86d ago
Microsoft Exchange Zero-Day Under Attack, No Patch Available
→ No new info (linked only)
Tier D
The Hacker News87d ago
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
→ No new info (linked only)
Tier B
CERT-FR87d ago
Bulletin d'actualité CERTFR-2026-ACT-022 (18 mai 2026)
→ No new info (linked only)
Tier E
Hacker News88d ago
Microsoft Exchange: Zero-day vulnerability is being attacked
→ No new info (linked only)
Tier D
CSO Online89d ago
Exchange Server zero-day vulnerability can be triggered by opening a malicious email
→ No new info (linked only)
Tier D
Heise Security89d ago
Microsoft Exchange: Zero-Day-Lücke wird angegriffen
→ No new info (linked only)
Tier B
CCCS Canada90d ago
Microsoft security advisory (AV26-473)
→ No new info (linked only)
Tier D
Infosecurity Magazine90d ago
Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers
→ No new info (linked only)
Tier D
SecurityWeek90d ago
Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild
→ No new info (linked only)
Tier B
BSI Advisories90d ago
[NEU] [hoch] Microsoft Exchange Server: Schwachstelle ermöglicht Cross-Site-Scripting- und Spoofing-Angriffe
→ No new info (linked only)
Tier D
Help Net Security90d ago
Unpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897)
→ No new info (linked only)
Tier D
BleepingComputer90d ago
Microsoft warns of Exchange zero-day flaw exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News90d ago
On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
→ No new info (linked only)
Tier B
CERT-FR90d ago
Vulnérabilité dans Microsoft Exchange Server (15 mai 2026)
→ No new info (linked only)
Tier B
CERT-FR90d ago
Vulnérabilité dans Microsoft Exchange Server (15 mai 2026)
→ No new info (linked only)
Tier C
VulDB90d ago
CVE-2026-42897 | Microsoft Exchange Server cross site scripting
→ No new info (linked only)
Tier A
Microsoft MSRC91d ago
CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:F/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897
CWECWE-79
PublishedMay 14, 2026
Last enriched63d agov13
Tags
zero-daycyberespionageweb shellmicrosoft exchangeEEMSsecurity updatesarbitrary code executionCISA KEV
Trending Score38
Source articles30
Independent16
Info Completeness12/14
Missing: epss, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 164
HIGHCVE-2026-68820EXPKEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Trending: 138
HIGHCVE-2026-45659EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 136
HIGHCVE-2026-50656EXP
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 92
CRITICALCVE-2026-50522EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 68

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 14, 2026
Added to CISA KEV
May 14, 2026
Discovered by ZDM
May 14, 2026
Updated: affectedVersions, tags
May 15, 2026
Updated: severity, affectedVersions
May 15, 2026
Updated: affectedVersions
May 15, 2026
Updated: affectedVersions
May 15, 2026
Updated: description, affectedVersions
May 15, 2026
Updated: affectedVersions, severity
May 15, 2026
Updated: affectedVersions
May 15, 2026
Updated: description
May 15, 2026
Updated: affectedVersions
May 18, 2026
Updated: tags
Jun 10, 2026
Updated: affectedVersions
Jun 10, 2026
Updated: description, tags
Jun 11, 2026
Actively Exploited
Jun 19, 2026
Exploit Available
Jun 19, 2026
Patch Available
Jun 19, 2026

Version History

v13
Last enriched 63d ago
v13Tier D63d ago

Updated description with technical details on exploitation and added patch release date.

descriptiontags
via SecurityWeek
v12Tier D64d ago

Updated affected versions to include Exchange Server 2016, 2019, and Subscription Edition, and added relevant tags.

affectedVersions
via BleepingComputer
v11Tier B64d ago

Updated patch availability to null and added new tags related to security updates and arbitrary code execution.

tags
via JPCERT/CC
v10Tier B87d ago

Updated affected versions to include specific cumulative updates and confirmed the patch URL.

affectedVersions
via CERT-FR
v9Tier D89d ago

Updated description with new technical details, specified affected versions, and noted that a patch is still in progress.

description
via CSO Online
v8Tier D89d ago

Updated severity to CRITICAL, added affected versions, and specified future patch availability.

affectedVersions
via Heise Security
v7Tier B90d ago

Updated severity to CRITICAL and added new affected versions for on-premises products.

affectedVersionsseverity
via CCCS Canada
v6Tier D90d ago

Updated description with more technical detail, added affected versions for Exchange Server Subscription Edition, 2016, and 2019, and noted that a permanent patch is not yet available.

descriptionaffectedVersions
via SecurityWeek
v5Tier D90d ago

Updated affected versions to include all existing versions of Exchange Server 2016, 2019, and Subscription Edition, and noted that no patch is currently available.

affectedVersions
via Infosecurity Magazine
v4Tier B90d ago

Added new affected versions for Microsoft Exchange Server.

affectedVersions
via CERT-FR
v3Tier D90d ago

Updated severity to CRITICAL, added affected version Subscription Edition RTM, and noted that a permanent fix is still in the works.

severityaffectedVersions
via Help Net Security
v2Tier D90d ago

Updated affected versions to include Exchange Server 2016, 2019, and Subscription Edition, and added patch information along with a new tag for EEMS.

affectedVersionstags
via BleepingComputer
v190d ago

Initial creation