EUVD-2026-30343
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 15 May 2026. Evidence sources: cisa_kev, eukev_kev.
- ENISA score
- 8.1 · CVSS 3.1
- Advisory evidence
- 1 linked advisory record
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2026-0159Kwetsbaarheid verholpen in Microsoft Exchange Server
