Junglewise Threat Intelligence

CVE-2026-62914: Microsoft Exchange Server cross-site scripting in web page generation

CVE-2026-62914 · Severity: high · CVSS 7.3 · Published 2026-08-11

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server contains a cross-site scripting (XSS) vulnerability in its web interface that allows an authorized attacker to inject malicious scripts. An attacker could use this flaw to spoof content, steal user credentials, or perform actions on behalf of legitimate users, compromising the integrity and trustworthiness of email communications and administrative functions.

Technical details

This vulnerability is an improper input neutralization (CWE-79: Cross-site Scripting) in Microsoft Exchange Server's web page generation. An authorized attacker can inject unsanitized input into the application, allowing execution of arbitrary JavaScript in the context of other users' browsers. The attack requires network access to the Exchange Server web interface and valid authentication credentials. Successful exploitation enables spoofing attacks, session hijacking, or theft of sensitive data. Patches are expected to be available from Microsoft's Security Response Center.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2026-08-11: disclosed

References

Related threats