Executive brief
Microsoft Exchange Server is a widely-deployed enterprise email and collaboration platform. A cross-site scripting (XSS) vulnerability in the web interface allows an attacker to inject malicious scripts that execute in users' browsers, potentially leading to session hijacking, credential theft, or email tampering without requiring special privileges.
Technical details
This is an improper input neutralization vulnerability (CWE-79, cross-site scripting) in Microsoft Exchange Server's web page generation. The vulnerability allows an unauthorized attacker to inject arbitrary script code that runs in the context of a user's browser session, enabling spoofing attacks. The attack vector is network-based and does not require prior authentication or user interaction beyond normal web browsing. An attacker can exploit this to perform credential harvesting, session hijacking, or malware distribution via the Exchange web interface. Patches are available from Microsoft Security Response Center.
Affected products
- Microsoft Exchange Server
Timeline
- 2026-09-08: disclosed