Zafiyet İstihbaratı

CVE-2026-42897 — Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

CVECVE-2026-42897CVSSEPSSExploitCISA KEVVendorMicrosoftÜrünMicrosoft

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

CISA tarafından önerilen aksiyon

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Bu içerik yararlı oldu mu?Geri bildirim bu cihazda saklanır; varsayılan olarak sunucuya gönderilmez.