Cross-Site Scripting Vulnerability in Microsoft Exchange Server by Microsoft
CVE-2026-69356

9.3CRITICAL

What is CVE-2026-69356?

A cross-site scripting vulnerability in Microsoft Exchange Server allows unauthorized attackers to inject malicious scripts into web pages. This can lead to data leakage and information spoofing, disrupting secure communications over a network. Prompt application of available security patches is essential to protect user data and maintain the integrity of the server.

Affected Version(s)

Microsoft Exchange Server 2016 Cumulative Update 23 x64-based Systems 15.01.0.0 < 15.01.2507.073

Microsoft Exchange Server 2019 Cumulative Update 14 x64-based Systems 15.02.0.0 < 15.02.1544.046

Microsoft Exchange Server 2019 Cumulative Update 15 x64-based Systems 15.02.0.0 < 15.02.1748.051

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.