{"@odata.context":"https://api.msrc.microsoft.com/sug/v2.0/sugodata/v2.0/en-US/$metadata#vulnerability/$entity","id":"00000000-0000-0000-0000-000054bd0741","releaseDate":"2026-05-14T07:00:00-07:00","cveNumber":"CVE-2026-42897","cveTitle":"Microsoft Exchange Server Spoofing Vulnerability","releaseNumber":"2026-May","vulnType":"Security Vulnerability","latestRevisionDate":"2026-07-14T07:00:00-07:00","description":"<p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.</p>\n","cweList":["CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"cweDetailsListForSearch":["cwe: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","cweUrl: https://cwe.mitre.org/data/definitions/79.html"],"unformattedDescription":"Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.","mitreText":"CVE-2026-42897","mitreUrl":"https://www.cve.org/CVERecord?id=CVE-2026-42897","publiclyDisclosed":"No","exploited":"Yes","latestSoftwareReleaseId":0,"latestSoftwareRelease":"Exploitation Detected","olderSoftwareReleaseId":0,"denialOfService":"N/A","tag":"Microsoft Exchange Server","issuingCna":"Microsoft","issuingCnaId":100000001,"severityId":100000000,"severity":"Critical","impactId":100000008,"impact":"Spoofing","langCode":"en-US","baseScore":"8.1","temporalScore":"7.5","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:F/RL:O/RC:C","vectorStringSource":"Microsoft","isMariner":false,"customerActionRequired":true,"customerActionRequiredId":1,"cweDetailsList":[{"keys":["cwe","cweUrl"],"values":["CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","https://cwe.mitre.org/data/definitions/79.html"]}],"articles":[{"title":"Microsoft Exchange Server Spoofing Vulnerability","articleType":"100000000","description":"<p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.</p>\n","ordinal":10000},{"title":"FAQ-Reference - CVE-2026-42897","articleType":"FAQ","description":"<p><strong>How could an attacker exploit this vulnerability?</strong></p>\n<p>An attacker could exploit this issue by sending a specially crafted email to a user. If the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.</p>\n<p><strong>How do I protect my Exchange Server from this vulnerability?</strong></p>\n<p>The Exchange Emergency Mitigation Service will provide mitigation automatically, and is on by default.  If it is not already enabled on your Exchange Server, you need to enable <a href=\"https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service\">Exchange Emergency Mitigation Service</a>.  You can find more information and instruction in the Exchange blog <a href=\"https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498\">here</a>.</p>\n<p><strong>Am I protected from this vulnerability if I am running Internet Explorer or Edge with Internet Explorer Mode?</strong></p>\n<p>No, because Content Security Policy (CSP) is not supported by Internet Explorer nor Microsoft Edge using Internet Explorer Mode. To stay protected, please make sure to not use Internet Explorer (Mode) to access OWA.</p>\n<h3 id=\"update-7142026\">Update 7/14/2026</h3>\n<p>Microsoft recommends installing the July 2026 Security Updates for your version of Exchange Server as soon as possible to be protected from this vulnerability and related CVE-2026-55008 vulnerability. Mitigations that have been applied either using the Exchange Emergency Mitigation Service or the EOMT script can be removed after July 2026 update is installed. Please see the <a href=\"https://techcommunity.microsoft.com/blog/exchange/released-july-2026-exchange-server-security-updates/4534146\">Exchange blog post</a> for more information.</p>\n","ordinal":10000}],"revisions":[{"cveNumber":"CVE-2026-42897","version":2.1,"revisionDate":"2026-07-14T07:00:00-07:00","initialDate":"0001-01-01T00:00:00Z","description":"<p>Updated FAQ information. This is an informational change only.</p>\n","unformattedDescription":"Updated FAQ information. This is an informational change only.","notificationNeeded":true,"notificationSent":false,"sourceId":"52520d91-bd7f-f111-93a1-000d3ac5fb71"},{"cveNumber":"CVE-2026-42897","version":1,"revisionDate":"2026-05-14T07:00:00-07:00","initialDate":"0001-01-01T00:00:00Z","description":"<p>Information published.</p>\n","unformattedDescription":"Information published.","notificationNeeded":false,"notificationSent":false,"sourceId":"60ddd49c-054b-f111-93fa-000d3afbc7d7"},{"cveNumber":"CVE-2026-42897","version":1.1,"revisionDate":"2026-05-18T07:00:00-07:00","initialDate":"0001-01-01T00:00:00Z","description":"<p>Updated FAQ information. This is an informational change only.</p>\n","unformattedDescription":"Updated FAQ information. This is an informational change only.","notificationNeeded":true,"notificationSent":true,"sourceId":"e0a5c1b4-d952-f111-93fb-000d3afbc7d7"},{"cveNumber":"CVE-2026-42897","version":2,"revisionDate":"2026-06-09T07:00:00-07:00","initialDate":"0001-01-01T00:00:00Z","description":"<p>Added links to June 2026 Exchange Server security updates.  Microsoft recommends installing this updates as soon as possible.</p>\n","unformattedDescription":"Added links to June 2026 Exchange Server security updates.  Microsoft recommends installing this updates as soon as possible.","notificationNeeded":true,"notificationSent":true,"sourceId":"ab7e7c0d-0c61-f111-93fb-000d3afbc7d7"}]}