logo

A Vulnerability in Microsoft Exchange Server Could Allow for Arbitrary Code Execution

ID: 90ca4dff-37ea-5e1c-b783-82ce67a53e3c

STIX ID: report--90ca4dff-37ea-5e1c-b783-82ce67a53e3c

Feed Name: CISecurity.org Advisories

Threat Score
55/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

...
...

### Executive Summary A cross-site scripting (XSS) vulnerability has been identified in Microsoft Exchange Server's Outlook Web Access that allows an attacker to execute arbitrary JavaScript in the victim's browser by sending a specially crafted email; exploitation can enable data theft, installation of malware, or account/browser hijacking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.