Junglewise Threat Intelligence

CVE-2026-69356: Microsoft Exchange Server cross-site scripting in web page generation

CVE-2026-69356 · Severity: critical · CVSS 9.3 · Published 2026-09-08

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server is a widely-deployed enterprise email and collaboration platform. A cross-site scripting (XSS) vulnerability in the web interface allows an attacker to inject malicious scripts that execute in users' browsers, potentially leading to session hijacking, credential theft, or email tampering without requiring special privileges.

Technical details

This is an improper input neutralization vulnerability (CWE-79, cross-site scripting) in Microsoft Exchange Server's web page generation. The vulnerability allows an unauthorized attacker to inject arbitrary script code that runs in the context of a user's browser session, enabling spoofing attacks. The attack vector is network-based and does not require prior authentication or user interaction beyond normal web browsing. An attacker can exploit this to perform credential harvesting, session hijacking, or malware distribution via the Exchange web interface. Patches are available from Microsoft Security Response Center.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2026-09-08: disclosed

References

Related threats