Executive brief
A security vulnerability exists in Microsoft Exchange Server, the platform used by organizations for email, calendaring, and collaboration. An attacker could exploit this flaw to perform spoofing attacks, potentially tricking users into revealing sensitive information or performing unauthorized actions. This could lead to unauthorized access to corporate communications or the compromise of user accounts.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft Exchange Server due to improper neutralization of input during web page generation (CWE-79). An unauthenticated attacker can exploit this over the network by inducing a user to interact with a malicious link or crafted content. Successful exploitation allows the attacker to perform spoofing, potentially leading to high impacts on confidentiality and integrity. The vulnerability is tracked as CVE-2026-47631 and has a CVSS 3.1 base score of 8.1.
Affected products
- Microsoft Exchange Server
Timeline
- 2026-06-09: disclosed: Initial publication of the CVE record.
- 2026-06-09: advisory: Microsoft released the security advisory.