Evidence dossier

CVE-2026-42897

Microsoft Exchange Server Spoofing Vulnerability

Exploited in the wild (CISA KEV since May 15, 2026). NVD reports CVSS 3.1 6.1. Severity assessments differ within at least one CVSS version. EPSS estimates 71.2% exploit likelihood as of Aug 27, 2026.

75.684.3Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

State
PUBLISHED
Published
May 14, 2026
Updated
Jun 19, 2026
Evidence coverage
86%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    microsoft

    Record text: Microsoft Exchange Server Spoofing Vulnerability

    Inspect raw assertion
    Field
    container
    Value
    Microsoft Exchange Server Spoofing Vulnerability
    Original evidence ↗
  3. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Microsoft Exchange Server Cross-Site Scripting Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Microsoft Exchange Server Cross-Site Scripting Vulnerability
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 71.21% probability · 99.36th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.712050000000; percentile 0.993600000000
    Original evidence ↗

Assessments differ

NVD6.1CVSS 3.1 · source date omitted
secure@microsoft.com8.1CVSS 3.1 · source date omitted

Values are shown separately by source and CVSS version.

ExploitationCatalog member

CISA KEV · catalog date May 15, 2026 · first observed Jul 19, 2026

Exploit likelihood71.20%

FIRST EPSS · score date Aug 27, 2026 · 99.4th percentile · first observed Aug 27, 2026

SeverityAssessments differ

NVD · CVSS 3.1 · first observed Jul 19, 2026 · values shown separately below

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
microsoftOriginal assertion
Record text

Microsoft Exchange Server Spoofing Vulnerability

Inspect raw assertion
Field
container
Value
Microsoft Exchange Server Spoofing Vulnerability
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Microsoft Exchange Server Cross-Site Scripting Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

71.21% probability · 99.36th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.712050000000; percentile 0.993600000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
40Underlying assertions
2Canonical products
40Target assertions
0Constraint assertions

Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

6 scope groups

microsoft · source assertedMicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23Direct source scope
Affected: 15.01.0.0 to before 15.01.2507.069 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "15.01.0.0", "lessThan": "15.01.2507.069", "versionType": "custom"}]
microsoft · source assertedMicrosoftMicrosoft Exchange Server 2019 Cumulative Update 14Direct source scope
Affected: 15.02.0.0 to before 15.02.1544.041 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "15.02.0.0", "lessThan": "15.02.1544.041", "versionType": "custom"}]
microsoft · source assertedMicrosoftMicrosoft Exchange Server 2019 Cumulative Update 15Direct source scope
Affected: 15.02.0.0 to before 15.02.1748.046 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "15.02.0.0", "lessThan": "15.02.1748.046", "versionType": "custom"}]
microsoft · source assertedMicrosoftMicrosoft Exchange Server Subscription Edition RTMDirect source scope
Affected: 15.02.0.0 to before 15.02.2562.043 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "15.02.0.0", "lessThan": "15.02.2562.043", "versionType": "custom"}]
NVD CPE · APPLICATIONmicrosoftexchange_serverVulnerable target · 39 assertions
Version 2016; Version 2019Canonical identity product-d87daca995d075bf30565cc429e7242a47683272975068df1d327ec1d8ff609cLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    104f96dc-e280-4e0a-8586-b043b55888c2
  2. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    28fca0e8-7d27-4746-9731-91b834ca3e64
  3. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8a9fb275-7f17-48b2-b528-be89309d2af5
  4. cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    40d8a6db-9225-4a3f-ad76-192f6cccf002
  5. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4df5bdb5-205d-4b64-a49a-0152afcf4a13
  6. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8c98993b-82a5-48cc-947f-896cea0cdb7f
  7. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    996163e7-6f3f-4d3b-aea4-62a7f7e1f54d
  8. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ca2ce223-aa49-49e6-ac32-59270eff55ad
  9. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5211792e-5292-41c0-b7e9-8aa63ec606ee
  10. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fe401b0a-dde4-4a36-8e27-6db14e094be2
  11. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    435343a4-bf10-461a-abf2-d511a5fbda75
  12. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4830d6a9-af74-480c-8f69-8648cd619980
  13. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    051de6c4-7456-4c42-bc51-253208aadb4e
  14. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b23c8e3e-5243-4da6-b9aa-f6053084b55e
  15. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b4185347-eedd-4239-9ab3-410e2ec89d2a
  16. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9be04790-85a2-4078-88ce-1787bc5172e7
  17. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    55284cf7-0d04-4216-83fe-4b1f9ca94207
  18. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ee320413-d2c9-4b28-89bf-361b44a3f0ff
  19. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ccf101be-27fd-4e2d-a694-c606bd3d1ed7
  20. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    73b3b3fe-7e85-4b86-a983-2c410ffef4b8
  21. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    29805ec7-6403-44b9-91ec-109c087e98eb
  22. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    449ce85b-e599-44d3-a7c1-5133f6a55e86
  23. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    44ecf39a-1de1-4870-a494-06a53494338d
  24. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    079e1e3f-ff25-4b0d-ac98-191d6455a014
  25. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    36ce5c6d-9a04-41f5-ae7c-265779833649
  26. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    583745c7-b802-4cbe-bd88-b5b9af9b5371
  27. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_21:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3be427a4-b0c2-4064-8234-29426325c348
  28. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ff76aeda-e574-40ed-b64f-8fdef8cac802
  29. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    23015889-48af-40a5-862f-290e73a54e77
  30. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    075e907f-af2f-4c31-86c7-51972be412a1
  31. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    63e362cb-cf75-4b7e-a4b1-d6d84afcbb68
  32. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    450319c4-7c8f-43b7-b7f8-80da4f1f2817
  33. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    71cdf29b-116b-4de2-afd0-b62477ff0aeb
  34. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    19c1ee0c-b8dd-4b91-be4b-1c42d72fb718
  35. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    56728785-188c-470a-9692-e6c7235109ca
  36. cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d4ab3c25-cea8-4d66-aee4-953c8b17911a
  37. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4fc34516-d7e7-4ad9-9b45-5474831548e0
  38. cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8039fba1-73d4-4ff2-b183-0dcc961cbff7
  39. cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    69af19dc-3d65-49a8-a85f-511085cdf27b
NVD CPE · APPLICATIONmicrosoftexchange_server_subscription_editionVulnerable target · 1 assertions
Any version (unconstrained) (< 15.02.2562.043)Canonical identity product-968220310b851685194a7006c2d3ffd575526a5f1b95af28bd69ba4fddaebff2Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:microsoft:exchange_server_subscription_edition:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    through excluding 15.02.2562.043
    Match ID
    a4db559b-001d-487d-8ea2-36f8ad7baf51

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

6.1
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
8.1
secure@microsoft.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
8.1
microsoftCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:F/RL:O/RC:C

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.