CVE-2026-69356
massUnauthenticated Cross-Site Scripting (Spoofing) in Microsoft Exchange Server
CVE-2026-69356 is a cross-site scripting flaw (CWE-79) in Microsoft Exchange Server caused by improper neutralization of input during web page generation. An unauthenticated remote attacker can submit crafted input that, when rendered in a page generated by Exchange and viewed by a user (user interaction is required), executes as content in that user's browser session. Successful exploitation is rated by Microsoft as spoofing: the injected content can impersonate trusted Exchange content or a trusted user, and the CVSS scope-change rating with high confidentiality and integrity impact indicates the attacker's effect crosses into the victim's security context. All organizations running the affected on-premises Microsoft Exchange Server deployments are potentially affected; the source data does not specify which Exchange releases or updates are impacted, so administrators must consult Microsoft's advisory. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.7% probability of exploitation within 30 days, so no active exploitation is currently known.
What to do: Review Microsoft's advisory for CVE-2026-69356 and apply the security update it specifies for your Exchange Server release as soon as practical, since the data does not list affected builds or patched versions. In the interim, reduce exposure by limiting internet access to Exchange web endpoints (e.g., restrict OWA/EAC to VPN or trusted networks) and advise users to be cautious of unexpected content or prompts in Exchange web pages. Because no PoC or in-the-wild exploitation is known yet, prioritize internet-facing Exchange servers first and monitor Microsoft and CISA channels for updates on active exploitation.
| Microsoft Exchange Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.