Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3486 articles · 168514 vulns · 36/41 feeds (7d)
← Back to list
8.1
CVE-2026-42897KEVEXPLOITEDPATCHED
microsoft · exchange_server

Microsoft Exchange Server Spoofing Vulnerability

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Affected Products

VendorProductVersions
microsoftexchange_server15.01.0.0, 15.02.0.0, 15.02.0.0, 15.02.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftmicrosoft exchange server 2019 cumulative updatemitre_affected90%
microsoftmicrosoft exchange server subscription edition rtmmitre_affected90%
microsoftexchangecert_advisory90%
microsoftexchange_server_subscription_editioncve_cpe95%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897(vendor-advisory, patch)

Related News (22 articles)

Tier B
JPCERT/CC
Security Alert: Microsoft Releases June 2026 Security Updates
→ No new info (linked only)
Tier D
SecurityWeek18d ago
Microsoft Patches Exploited Exchange Server Vulnerability
→ No new info (linked only)
Tier D
CSO Online18d ago
June Patch Tuesday marks a ‘new normal’ with over 200 CVEs, 32 rated ‘critical’
→ No new info (linked only)
Tier D
BleepingComputer18d ago
Microsoft patches Exchange Server zero-day exploited in attacks
→ No new info (linked only)
Tier D
BleepingComputer19d ago
Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws
→ No new info (linked only)
Tier D
Dark Reading41d ago
Microsoft Exchange Zero-Day Under Attack, No Patch Available
→ No new info (linked only)
Tier D
The Hacker News41d ago
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
→ No new info (linked only)
Tier B
CERT-FR42d ago
Bulletin d'actualité CERTFR-2026-ACT-022 (18 mai 2026)
→ No new info (linked only)
Tier E
Hacker News43d ago
Microsoft Exchange: Zero-day vulnerability is being attacked
→ No new info (linked only)
Tier D
CSO Online44d ago
Exchange Server zero-day vulnerability can be triggered by opening a malicious email
→ No new info (linked only)
Tier D
Heise Security44d ago
Microsoft Exchange: Zero-Day-Lücke wird angegriffen
→ No new info (linked only)
Tier B
CCCS Canada45d ago
Microsoft security advisory (AV26-473)
→ No new info (linked only)
Tier D
Infosecurity Magazine45d ago
Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers
→ No new info (linked only)
Tier D
SecurityWeek45d ago
Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild
→ No new info (linked only)
Tier B
BSI Advisories45d ago
[NEU] [hoch] Microsoft Exchange Server: Schwachstelle ermöglicht Cross-Site-Scripting- und Spoofing-Angriffe
→ No new info (linked only)
Tier D
Help Net Security45d ago
Unpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897)
→ No new info (linked only)
Tier D
BleepingComputer45d ago
Microsoft warns of Exchange zero-day flaw exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News45d ago
On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
→ No new info (linked only)
Tier B
CERT-FR45d ago
Vulnérabilité dans Microsoft Exchange Server (15 mai 2026)
→ No new info (linked only)
Tier B
CERT-FR45d ago
Vulnérabilité dans Microsoft Exchange Server (15 mai 2026)
→ No new info (linked only)
Tier C
VulDB45d ago
CVE-2026-42897 | Microsoft Exchange Server cross site scripting
→ No new info (linked only)
Tier A
Microsoft MSRC45d ago
CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:F/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897
CWECWE-79
PublishedMay 14, 2026
Last enriched18d agov13
Tags
zero-daycyberespionageweb shellmicrosoft exchangeEEMSsecurity updatesarbitrary code executionCISA KEV
Trending Score12
Source articles22
Independent15
Info Completeness12/14
Missing: epss, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-45585EXP
Windows BitLocker Security Feature Bypass Vulnerability
Trending: 36
HIGHCVE-2026-33825EXPKEV
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 28
HIGHCVE-2026-41091EXPKEV
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 28
MEDIUMCVE-2026-45498EXPKEV
Microsoft Defender Denial of Service Vulnerability
Trending: 26
CRITICALCVE-2026-45480
Azure Active Directory Elevation of Privilege Vulnerability
Trending: 24

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 14, 2026
Added to CISA KEV
May 14, 2026
Discovered by ZDM
May 14, 2026
Updated: affectedVersions, tags
May 15, 2026
Updated: severity, affectedVersions
May 15, 2026
Updated: affectedVersions
May 15, 2026
Updated: affectedVersions
May 15, 2026
Updated: description, affectedVersions
May 15, 2026
Updated: affectedVersions, severity
May 15, 2026
Updated: affectedVersions
May 15, 2026
Updated: description
May 15, 2026
Updated: affectedVersions
May 18, 2026
Updated: tags
Jun 10, 2026
Updated: affectedVersions
Jun 10, 2026
Updated: description, tags
Jun 11, 2026
Actively Exploited
Jun 19, 2026
Exploit Available
Jun 19, 2026
Patch Available
Jun 19, 2026

Version History

v13
Last enriched 18d ago
v13Tier D18d ago

Updated description with technical details on exploitation and added patch release date.

descriptiontags
via SecurityWeek
v12Tier D18d ago

Updated affected versions to include Exchange Server 2016, 2019, and Subscription Edition, and added relevant tags.

affectedVersions
via BleepingComputer
v11Tier B19d ago

Updated patch availability to null and added new tags related to security updates and arbitrary code execution.

tags
via JPCERT/CC
v10Tier B42d ago

Updated affected versions to include specific cumulative updates and confirmed the patch URL.

affectedVersions
via CERT-FR
v9Tier D44d ago

Updated description with new technical details, specified affected versions, and noted that a patch is still in progress.

description
via CSO Online
v8Tier D44d ago

Updated severity to CRITICAL, added affected versions, and specified future patch availability.

affectedVersions
via Heise Security
v7Tier B44d ago

Updated severity to CRITICAL and added new affected versions for on-premises products.

affectedVersionsseverity
via CCCS Canada
v6Tier D45d ago

Updated description with more technical detail, added affected versions for Exchange Server Subscription Edition, 2016, and 2019, and noted that a permanent patch is not yet available.

descriptionaffectedVersions
via SecurityWeek
v5Tier D45d ago

Updated affected versions to include all existing versions of Exchange Server 2016, 2019, and Subscription Edition, and noted that no patch is currently available.

affectedVersions
via Infosecurity Magazine
v4Tier B45d ago

Added new affected versions for Microsoft Exchange Server.

affectedVersions
via CERT-FR
v3Tier D45d ago

Updated severity to CRITICAL, added affected version Subscription Edition RTM, and noted that a permanent fix is still in the works.

severityaffectedVersions
via Help Net Security
v2Tier D45d ago

Updated affected versions to include Exchange Server 2016, 2019, and Subscription Edition, and added patch information along with a new tag for EEMS.

affectedVersionstags
via BleepingComputer
v145d ago

Initial creation