Skip to content

CVE-2026-69356

Microsoft Exchange Server cross-site scripting allows spoofing over a network (CVE-2026-69356)

Critical 9.3 Vendor: Microsoft Published

Microsoft Exchange Server 2016 CU23, 2019 CU14/CU15 and Subscription Edition RTM are affected by a cross-site scripting flaw with a CVSS 9.3 critical rating. Microsoft has released fixed builds in the September 2026 security updates.

What happened

This is a cross-site scripting vulnerability (CWE-79) in Microsoft Exchange Server. Microsoft describes it as improper neutralization of input during web page generation, allowing an unauthorized attacker to perform spoofing over a network. The CVSS vector indicates the attack can be carried out remotely with low complexity and no privileges, but requires a person to interact with malicious web content. A successful exploit can have a high impact on confidentiality and integrity, and because scope changes it can affect resources beyond the vulnerable component. There is no impact on availability.

No exploitation in the wild, public disclosure, or CISA KEV entry is recorded in the data available for this page.

Who is affected

Affected products and version ranges are:

  • Microsoft Exchange Server 2016 Cumulative Update 23: 15.01.0.0 to before 15.01.2507.073
  • Microsoft Exchange Server 2019 Cumulative Update 14: 15.02.0.0 to before 15.02.1544.046
  • Microsoft Exchange Server 2019 Cumulative Update 15: 15.02.0.0 to before 15.02.1748.051
  • Microsoft Exchange Server Subscription Edition RTM: 15.02.0.0 to before 15.02.2562.049

These are on-premises Microsoft Exchange Server builds, typically used for email, calendar and identity-related services. Check each Exchange server's build number against the affected ranges.

What to do now

  1. Apply the security update for the Exchange Server build you run. The fixed builds from Microsoft are:
  • Microsoft Exchange Server 2016 Cumulative Update 23: 15.01.2507.073 (KB5121611)
  • Microsoft Exchange Server 2019 Cumulative Update 14: 15.02.1544.046 (KB5121610)
  • Microsoft Exchange Server 2019 Cumulative Update 15: 15.02.1748.051 (KB5121609)
  • Microsoft Exchange Server Subscription Edition RTM: 15.02.2562.049 (KB5121608)
  1. After installation, verify the build number on each Exchange server to confirm it is at or above the fixed build for that cumulative update.
  2. Microsoft has not listed a workaround. If you cannot patch immediately, limit access to Exchange web components and remind staff to be cautious with unexpected prompts or links, because exploitation requires user interaction.

Beyond the patch

Patch first. Exchange is typically an internet-facing system that manages identity and mail, which is the exposure reviewed by Virtual CISO Services (vCISO) and the attack path monitored by Managed Detection & Response (MDR). Once the update is applied, check whether Exchange web endpoints need to be publicly reachable and make sure mail and identity-based behaviour is watched, so the next Exchange vulnerability is contained earlier.

Affected and fixed versions

ProductAffectedFixed in
Microsoft Exchange Server 2016 Cumulative Update 2315.01.0.0 – < 15.01.2507.07315.01.2507.073
Microsoft Exchange Server 2019 Cumulative Update 1415.02.0.0 – < 15.02.1544.04615.02.1544.046
Microsoft Exchange Server 2019 Cumulative Update 1515.02.0.0 – < 15.02.1748.05115.02.1748.051
Microsoft Exchange Server Subscription Edition RTM15.02.0.0 – < 15.02.2562.04915.02.2562.049

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.