Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
Published: 2026-08-11
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input during web page generation creates a cross‑site scripting (CWE‑79) vulnerability that allows an authorized attacker to inject malicious content. By manipulating the rendered page, the attacker can spoof the identity of legitimate users or services, potentially leading to deception, unauthorized disclosure, or facilitation of further attacks within the network.

Affected Systems

Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Exchange Server Subscription Edition RTM are affected by this vulnerability.

Risk and Exploitability

The CVSS score of 7.3 indicates a moderate‑to‑high severity, while the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with sufficient privileges to generate web pages; the attacker would then inject XSS payloads that manipulate page content to perform spoofing across the network.

Generated by OpenCVE AI on August 12, 2026 at 16:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the Microsoft Exchange Server cumulative updates that contain the correction for CVE‑2026‑62914 (CU23 for Exchange 2016, CU14/15 for Exchange 2019, and the appropriate update for Subscription Edition).
  • Configure the Exchange web interface to perform strict input validation and output encoding so that all user‑supplied data is safely rendered, reducing the risk of XSS vectors.
  • Continuously monitor web traffic logs and Exchange event logs for anomalous page generation or spoofing attempts, and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 12, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
Title Microsoft Exchange Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server 2016 Exchange Server 2019 Exchange Server Se
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-12T14:47:57.371Z

Reserved: 2026-07-14T21:25:21.036Z

Link: CVE-2026-62914

cve-icon Vulnrichment

Updated: 2026-08-12T13:50:40.417Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-11T17:18:45.447

Modified: 2026-08-12T14:18:25.947

Link: CVE-2026-62914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T16:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')