Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-14
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input during web page generation creates a classic cross‑site scripting flaw. By injecting malicious script into the HTML pages served by Microsoft Exchange Server, an attacker can have that script executed in the browsers of unsuspecting users, allowing the attacker to present forged content and impersonate the server or domain on a network.

Affected Systems

Microsoft Exchange Server 2016 with Cumulative Update 23, Microsoft Exchange Server 2019 with Cumulative Updates 14 and 15, and the Subscription Edition at release time (RTM) are listed as affected by Microsoft. These versions are included in the CNA vendor/product data and in the affected CPEs.

Risk and Exploitability

The CVSS score of 9.6 marks the flaw as critical, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The likely attack vector is a crafted web request to the Exchange Server’s remote interface. The vulnerability is not listed in the CISA KEV catalog, implying no known weaponized use. Attackers would need to send a crafted web request to a vulnerable Exchange Server’s remote interface to trigger the XSS payload, targeting the web services that generate HTML output.

Generated by OpenCVE AI on August 1, 2026 at 09:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the cumulative update 23 for Exchange 2016, the cumulative update 14 or 15 for Exchange 2019, or the latest release for the Subscription Edition to address the XSS flaw.
  • If a patch cannot be applied immediately, restrict or sanitize HTTP requests to the Exchange Web Services endpoints that generate HTML output, blocking or escaping script tags in input data.
  • Enable a Content Security Policy on the Exchange Server and enforce anti‑XSS filters to prevent execution of injected scripts until a patch is deployed.

Generated by OpenCVE AI on August 1, 2026 at 09:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Exchange Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server 2016 Exchange Server 2019 Exchange Server Se
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:22:38.565Z

Reserved: 2026-06-16T14:12:44.283Z

Link: CVE-2026-55008

cve-icon Vulnrichment

Updated: 2026-07-15T10:59:27.731Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')