Microsoft confirms attackers are exploiting CVE-2026-42897, a new Outlook Web Access zero-day in on-premises Exchange Server
Microsoft has confirmed attackers are actively exploiting CVE-2026-42897, a cross-site scripting flaw in on-premises Exchange Server's Outlook Web Access. A crafted email can run arbitrary JavaScript when opened in OWA. There is no permanent patch, but Microsoft's Exchange Emerge
Microsoft has confirmed attackers are actively exploiting CVE-2026-42897, a cross-site scripting flaw in on-premises Exchange Server's Outlook Web Access. A crafted email can run arbitrary JavaScript when opened in OWA. There is no permanent patch, but Microsoft's Exchange Emergency Mitigation Service auto-applies a fix on default-enabled systems. CISA added the bug to its Known Exploited Vulnerabilities catalog with a May 29 deadline for federal civilian agencies.
Published on