Critical Analysis: CVE-2026-42897 - Microsoft Exchange Server Cross-Site Scripting Vulnerability... — May 20, 2026
Published 20 May 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news
AGMP Partners Initial Discovery and Context Just yesterday, on May 20, 2026, Microsoft dropped a patch for CVE-2026-42897, an insidious Cross-Site Scripting (XSS) vulnerability impacting Microsoft Exchange Server. This isn't just another arbitrary XSS; it's within Exchange, a critical-path service for most enterprises, often exposed to the internet. Our team at AGMP Partners has been poring over the details since the bulletin hit, and frankly, it's a nasty one, warranting a CVSSv3 score of 7.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). The "N" for Network access vector, "L" for Low attack complexity, and the fact that it requires user interaction ("UI:R") are key here. Although authenticated users are typically needed for most Exchange XSS issues, the specifics of this CVE indicate that an unauthenticated attacker could potentially coerce an authenticated user into triggering the pa