Executive brief
Microsoft Exchange Server, the widely used corporate email and calendaring platform, is vulnerable to a security flaw in its Outlook Web Access (OWA) component. An attacker can use this vulnerability to run malicious scripts in a user's web browser if the user interacts with a specially crafted link or page. This could allow an attacker to steal sensitive session information, impersonate users, or gain unauthorized access to corporate email accounts.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Microsoft Exchange Server due to improper neutralization of input during web page generation within Outlook Web Access (OWA). The vulnerability is classified as CWE-79 and allows an unauthenticated, remote attacker to execute arbitrary JavaScript in the context of a victim's browser. Exploitation requires a network-based attack vector and user interaction, such as clicking a malicious link. Successful exploitation can lead to session hijacking, unauthorized data access, and spoofing. This vulnerability has been reported as exploited in the wild.
Affected products
- Microsoft Exchange Server
Timeline
- 2026-05-14: disclosed
- 2026-05-15: advisory: NVD publication date
- 2026-05-15: exploited: Reported as exploited in the wild in advisory metadata.