CVE-2026-62914
EUVD-2026-5641611.08.2026, 17:18
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| microsoft | exchange_server | 𝑥 < 15.02.2562.046 |
| microsoft | exchange_server | 15.1.0.0 ≤ 𝑥 < 15.1.2507.72 |
| microsoft | exchange_server | 15.2.0.0 ≤ 𝑥 < 15.2.1748.49 |
| microsoft | exchange_server | 15.2.0.0 ≤ 𝑥 < 15.2.1544.44 |
𝑥
= Vulnerable software versions
Vulnerability Media Exposure