Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft exchange Server
Microsoft exchange Server Subscription Edition |
|
| CPEs | cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_21:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_2:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_3:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_4:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_5:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_6:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_7:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_10:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_13:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server_subscription_edition:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft exchange Server
Microsoft exchange Server Subscription Edition |
Wed, 12 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |
| Title | Microsoft Exchange Server Spoofing Vulnerability | |
| First Time appeared |
Microsoft
Microsoft exchange Server 2016 Microsoft exchange Server 2019 Microsoft exchange Server Se |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft exchange Server 2016 Microsoft exchange Server 2019 Microsoft exchange Server Se |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-08-13T17:35:15.153Z
Reserved: 2026-07-14T21:25:21.036Z
Link: CVE-2026-62914
Updated: 2026-08-12T13:50:40.417Z
Status : Analyzed
Published: 2026-08-11T17:18:45.447
Modified: 2026-08-13T18:57:33.597
Link: CVE-2026-62914
No data.
OpenCVE Enrichment
Updated: 2026-08-12T16:30:05Z