ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-42897

CRITICAL Export PDF

Microsoft Microsoft Vulnerability

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

CVSS Score
9.8
CRITICAL
Published
15 May 2026 00:00
Modified
N/A
Vendor
Microsoft
Product
Microsoft
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-79

Affected Systems

Microsoft
Microsoft
Microsoft
Windows Ancillary Function Driver For WinSock
SharePoint
Active Directory Federation Services
SharePoint Server
Windows
DirectX
Internet Explorer
Defender
Microsoft
Office
Visual Basic For Applications (VBA)

KEV Status

Known Exploited Vulnerability