What is CVE-2026-42897?
CVE-2026-42897 is a vulnerability classified as Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), affecting Microsoft Exchange Server 2016 Cumulative Update 23 (affected versions: 15.01.0.0 – < 15.01.2507.069), Microsoft Exchange Server 2019 Cumulative Update 14 (affected versions: 15.02.0.0 – < 15.02.1544.041), Microsoft Exchange Server 2019 Cumulative Update 15 (affected versions: 15.02.0.0 – < 15.02.1748.046), and 1 more product. This vulnerability is rated High, with a CVSS score of 8.1. This vulnerability has been observed being exploited in the wild.
