Junglewise Threat Intelligence

CVE-2026-45500: Microsoft Exchange Server cross-site scripting

CVE-2026-45500 · Severity: medium · CVSS 6.1 · Published 2026-06-09

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Exchange Server, the platform used by organizations for email and calendaring, could allow an attacker to perform spoofing attacks. By tricking a user into interacting with a malicious link or page, an attacker can execute unauthorized scripts in the user's browser session. This could lead to the theft of sensitive information or unauthorized actions performed on behalf of the user within the email environment.

Technical details

Microsoft Exchange Server contains a cross-site scripting (XSS) vulnerability due to improper neutralization of input during web page generation (CWE-79). An unauthenticated attacker can exploit this by sending a specially crafted link to a user and inducing them to click it. Successful exploitation allows the attacker to execute malicious scripts in the context of the victim's browser session, potentially leading to session hijacking or the unauthorized disclosure of information. The vulnerability is rated with a CVSS 3.1 score of 6.1, reflecting a network attack vector and required user interaction.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2026-06-09: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats