Microsoft Exchange Server on-premises OWA zero-day CVE-2026-42897 under active attack with no permanent patch
Every on-prem Microsoft $MSFT Exchange Server 2016, 2019, and Subscription Edition is under active attack. OWA zero-day CVE-2026-42897 lets a crafted email run JavaScript in an authenticated session, stealing tokens and impersonating mailboxes. No permanent patch exists yet.
Every on-premises Microsoft $MSFT Exchange Server in production today running 2016, 2019, or the Subscription Edition is under active attack, and there is no permanent patch. The vulnerability, tracked as CVE-2026-42897 with a CVSS score of 8.1, is a cross-site scripting flaw in the Outlook Web Access interface. The attack requires nothing more than a crafted email. The moment a recipient opens that email in OWA, JavaScript executes inside their authenticated browser session. From there an attacker can steal session tokens, impersonate mailboxes, and manipulate mail-routing rules, all without ever touching the server itself. Microsoft has confirmed exploitation in the wild and is currently working on a permanent patch. In the interim, the company is distributing a temporary mitigation labeled M2.1.x through the Exchange Emergency Mitigation Service. The mitigation deploys automatically via URL-rewrite configuration on Mailbox servers where EEMS is enabled, but air-gapped or disconnected environments require administrators to manually download the latest Exchange On-premises Mitigation Tool and apply it from an elevated Exchange Management Shell. CISA added CVE-2026-42897 to its Known Exploited Vulnerabilities catalog on May 15, giving Federal Civilian Executive Branch agencies until May 29 to apply mitigations. Exchange Online tenants are not affected by this flaw. Organizations still running on-premises Exchange should treat the mitigation deployment as urgent and verify EEMS status before assuming protection is in place.