
- Home
- Threat Advisories
- NCSC-TAD-2606-001
NCSC-TAD-2606-001
Severity Level: High
Vulnerability
Reference No.: NCSC-TAD-2606-001CVSS 0
Microsoft Exchange Server XSS Vulnerability
- Threat Type:
- N/A
- TLP:
- CLEAR
- CVE:
- CVE-2026-42897
Overview
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Affected Technologies
- Microsoft Exchange Outlook Web Access (OWA)
Mitigation and Immediate Actions
- 01
Apply the latest Exchange Server security updates and maintain existing mitigations as an additional layer of defence.
- 02
Exchange Emergency Mitigation (EM) Service: Block mitigation M2 from re-applying and remove the M2 IIS rules.
- 03
EOMT script: Roll back the mitigation.

