Description
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-02-10
Score: 6.5 Medium
EPSS: 9.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a user interface misrepresentation that enables an adversary to spoof critical information displayed over the network. This flaw allows an unauthorized attacker to impersonate legitimate communications or services, potentially misleading users into revealing credentials or executing actions they otherwise would not. The weakness is categorized as CWE‑1286 (inconsistent interface semantics), CWE‑345 (boundary checking errors), and CWE‑451 (information exposure). The impact is primarily the compromise of data integrity and user trust, which may lead to credential theft or manipulation of mail flows.

Affected Systems

Affected Microsoft Exchange Server products include the 2016 Cumulative Update 23, the 2019 Cumulative Update 14 and 15, and the Subscription Edition Release To Manufacturing (RTM) version. These updates cover versioned releases of Exchange Server 2016 and 2019, making the vulnerability relevant to environments running any of those cumulative updates or the base subscription edition.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity, and the EPSS score of 9% suggests a low to moderate exploitation probability. The flaw is not listed in the CISA KEV catalog, implying no known large‑scale exploitation at present. The attack vector is inferred to be network‑based, leveraging normal traffic to the Exchange Server’s web interface without requiring elevated privileges. As the flaw resides in the client‑side UI, any user with access to the affected Exchange web portal could be deceived by the attacker.

Generated by OpenCVE AI on June 18, 2026 at 05:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Exchange Server security updates—Cumulative Update 23 for Exchange 2016, Cumulative Update 14 and 15 for Exchange 2019, or the Subscription Edition RTM—from the Microsoft Security Response Center.
  • Provide training to users on recognizing spoofed interfaces and phishing attempts, enhancing their ability to detect malicious UI changes.
  • Configure firewalls or a reverse proxy to restrict direct external access to Exchange servers and enforce TLS for all client connections.

Generated by OpenCVE AI on June 18, 2026 at 05:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 15 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft exchange Server Subscription Edition
CPEs cpe:2.3:a:microsoft:exchange_server:*:*:*:*:subscription:*:*:* cpe:2.3:a:microsoft:exchange_server_subscription_edition:*:*:*:*:*:*:*:*
Vendors & Products Microsoft exchange Server Subscription Edition

Thu, 12 Feb 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Exchange Server 2016 Cumulative Update 23
Microsoft microsoft Exchange Server 2019 Cumulative Update 14
Microsoft microsoft Exchange Server 2019 Cumulative Update 15
Microsoft microsoft Exchange Server Subscription Edition Rtm
Vendors & Products Microsoft microsoft Exchange Server 2016 Cumulative Update 23
Microsoft microsoft Exchange Server 2019 Cumulative Update 14
Microsoft microsoft Exchange Server 2019 Cumulative Update 15
Microsoft microsoft Exchange Server Subscription Edition Rtm

Wed, 11 Feb 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft exchange Server
CPEs cpe:2.3:a:microsoft:exchange_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_15:*:*:*:*:*:*
Vendors & Products Microsoft exchange Server

Wed, 11 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Description User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Exchange Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-1286
CWE-345
CWE-451
CPEs cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server Exchange Server 2016 Exchange Server 2019 Exchange Server Se Exchange Server Subscription Edition Microsoft Exchange Server 2016 Cumulative Update 23 Microsoft Exchange Server 2019 Cumulative Update 14 Microsoft Exchange Server 2019 Cumulative Update 15 Microsoft Exchange Server Subscription Edition Rtm
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-05-11T21:25:31.614Z

Reserved: 2025-12-30T18:10:54.846Z

Link: CVE-2026-21527

cve-icon Vulnrichment

Updated: 2026-02-11T15:33:21.425Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-10T18:16:35.093

Modified: 2026-06-17T10:18:47.190

Link: CVE-2026-21527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T05:00:17Z

Weaknesses
  • CWE-1286

    Improper Validation of Syntactic Correctness of Input

  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information