
- الصفحة الرئيسية
- نشرات التهديدات
- NCSC-TAD-2606-001
NCSC-TAD-2606-001
مستوى الخطورة: عالية
ثغرة
الرقم المرجعي: NCSC-TAD-2606-001CVSS 0
Microsoft Exchange Server XSS Vulnerability
- نوع التهديد:
- غير متوفر
- مستوى المشاركة (TLP):
- CLEAR
- CVE:
- CVE-2026-42897
نظرة عامة
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
التقنيات المتأثرة
- Microsoft Exchange Outlook Web Access (OWA)
إجراءات الحد من المخاطر والإجراءات الفورية
- 01
Apply the latest Exchange Server security updates and maintain existing mitigations as an additional layer of defence.
- 02
Exchange Emergency Mitigation (EM) Service: Block mitigation M2 from re-applying and remove the M2 IIS rules.
- 03
EOMT script: Roll back the mitigation.

