← back
CVE-2026-21527mediumCWE-1286CWE-345CWE-451

Microsoft Exchange Server Spoofing Vulnerability

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 7.7%
exploitation probability
7.7%top 6% of all CVEs
observed exploitation
nono source reports it
In short

Microsoft Exchange Server displays misleading information in its user interface, allowing attackers to trick users into believing false information. This can be exploited remotely to impersonate legitimate messages or actions.

Technical detail

A UI misrepresentation vulnerability in Microsoft Exchange Server enables attackers to spoof critical information over the network without authentication. The attack leverages improper display of security-relevant data in the user interface, potentially leading to unauthorized access or credential theft through social engineering.

Summary generated and translated by AI from the official description.
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C