Actively exploited Microsoft Exchange OWA zero-day CVE-2026-42897 fixed in June Patch Tuesday alongside 200 flaws
Anyone still running on-prem Microsoft Exchange $MSFT needs to patch now. CVE-2026-42897, a critical Outlook Web Access flaw that runs malicious code from a single crafted email, is under active exploitation. It is one of three zero-days in this week's Patch Tuesday, which closes
If your organization still runs Microsoft Exchange $MSFT on its own servers, this week's security update is not optional. Microsoft has confirmed that CVE-2026-42897, a critical flaw in the Outlook Web Access component, is being actively exploited in the wild. The attack needs nothing more than a crafted email: when a targeted user opens it in OWA, attacker-controlled code can run in their browser session, opening the door to account compromise and deeper intrusion. The flaw affects on-premises Exchange, including the Subscription Edition, 2019 and 2016 builds. Exchange Online is not affected. The patch arrived as part of Microsoft's June Patch Tuesday, which closed 200 vulnerabilities in total, including three publicly disclosed zero-days and 33 rated critical, most of them remote code execution issues. There is a catch for older deployments: only servers enrolled in the Extended Security Update program receive the fix automatically, while Subscription Edition customers get it by default. Organizations running unsupported builds outside that program stay exposed unless they upgrade. On-premises mail servers remain a high-value target because they sit at the center of corporate communication and often face the public internet. Administrators who cannot apply the update immediately should review Microsoft's OWA mitigations and restrict external access to the web client until patching is complete.