Key Takeaways

- CVE-2026-42897 allows remote attackers to execute JavaScript in OWA with zero privileges required
- CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by May 29
- Microsoft recommends keeping emergency mitigations in place even after installing the June 2026 security update
The Vulnerability Explained
Microsoft has patched CVE-2026-42897, a high-severity spoofing vulnerability in Exchange Server that attackers were actively exploiting before the fix arrived. The flaw enables cross-site scripting attacks against users of Outlook Web Access.
The vulnerability affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition. Remote attackers can exploit it without any privileges.
“An attacker could exploit this issue by sending a specially crafted email to a user. If the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.”
— Microsoft Exchange Team
The attack chain is straightforward. An attacker sends a malicious email. When the target opens it in OWA and certain conditions are met, JavaScript runs in their browser. That script executes within the user's authenticated session, potentially exposing sensitive data or enabling further compromise.
Timeline of Response
Microsoft first responded in mid-May by pushing temporary mitigations through its Exchange Emergency Mitigation Service. EEMS can automatically apply interim fixes to Exchange servers while permanent patches are in development.
The Cybersecurity and Infrastructure Security Agency moved quickly. On May 15, it added the vulnerability to its catalog of security flaws exploited in the wild. Federal agencies had until May 29 to patch their servers.
Patching Guidance
Microsoft is urging administrators to install the June 2026 security updates immediately. But there's an unusual twist: the company also recommends keeping the temporary mitigations in place.
"We recommend that customers keep the mitigation described in place," Microsoft stated. "The mitigation provides an additional layer of defense and helps ensure continuous protection as further improvements are released."
This belt-and-suspenders approach suggests Microsoft sees value in defense-in-depth here. The mitigations may catch edge cases or attack variants that emerge after the patch.
Exchange Server's Troubled Security History
CVE-2026-42897 joins a long list of Exchange Server vulnerabilities that attackers have exploited in real attacks. Over the past five years, CISA has added 20 Exchange Server flaws to its Known Exploited Vulnerabilities catalog. Ransomware gangs exploited 14 of those 20.
Exchange Server has been a prime target since the ProxyLogon and ProxyShell vulnerabilities in 2021 demonstrated how devastating on-premises email server compromises can be. State-sponsored groups and cybercriminals alike have treated Exchange as a high-value entry point into enterprise networks.
In October 2025, CISA and the National Security Agency released joint guidance on hardening Exchange servers against attacks. That guidance came weeks after Exchange 2016 and 2019 reached end of support.
The ESU Complication
Discussion in cybersecurity communities has highlighted a complication for organizations running older Exchange versions. Exchange Server 2016 and 2019 reached end of support in October 2025. Security patches for these versions now require Extended Security Update subscriptions.
That means organizations still running Exchange 2016 or 2019 without ESU cannot get this patch through normal channels. They either need to purchase ESU coverage, upgrade to Exchange Server SE, or migrate to Exchange Online.
This creates a two-tier security situation where paying customers get protection while others remain exposed. For organizations with tight budgets, this may force difficult decisions about which systems to prioritize.
What Administrators Should Do Now
- Verify your Exchange Server version and ESU coverage status
- Install the June 2026 security updates for your Exchange Server version
- Confirm that EEMS mitigations remain active even after patching
- Review OWA access logs for any signs of exploitation attempts
- Consider whether on-premises Exchange still makes sense for your organization
BleepingComputer reports it has not received a response from Microsoft about specific details of the attacks exploiting this vulnerability. The identity of the threat actors and scale of exploitation remain unknown.


Logicity's Take
Frequently Asked Questions
Which Exchange Server versions are affected by CVE-2026-42897?
Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition are all affected by this vulnerability.
Do I need special privileges to exploit this Exchange vulnerability?
No. Remote attackers can exploit CVE-2026-42897 with zero privileges. They only need to send a specially crafted email that the target opens in Outlook Web Access.
Should I remove the EEMS mitigations after installing the patch?
No. Microsoft explicitly recommends keeping the mitigations in place even after patching for additional defense-in-depth protection.
Can I get this patch if I'm running Exchange 2016 or 2019 without ESU?
No. Since these versions reached end of support in October 2025, security updates require an Extended Security Update subscription.
What is the CVSS score for CVE-2026-42897?
The vulnerability has a CVSS base score of 8.1, classifying it as high severity.
Need Help Implementing This?
Source: BleepingComputer
Broader Context: June 2026 Patch Tuesday and Additional Zero-Day Fixes
The new article provides broader context regarding the June 2026 'Patch Tuesday' update, which is identified as Microsoft's largest release ever, encompassing 206 total vulnerabilities. It introduces details on three additional, publicly disclosed zero-day vulnerabilities (CVE-2026-45586, CVE-2026-49160, and CVE-2026-50507) that were not mentioned in the original report.
Huma Shazia
Senior AI & Tech Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.
Related Articles
More in Cybersecurity
SD-WAN Security Flaw: What CEOs Must Do by Friday
CISA has flagged an actively exploited vulnerability in Cisco's SD-WAN Manager, giving federal agencies just four days to patch. For enterprises running Cisco SD-WAN infrastructure, this isn't just a government mandate. It's a wake-up call about network security debt that could cost millions in breach response.

Apache ActiveMQ Vulnerability: 6,400 Servers at Risk
A critical 13-year-old security flaw in Apache ActiveMQ is now being actively exploited, putting over 6,400 enterprise message brokers at immediate risk. For businesses running Java applications, this vulnerability could mean unauthorized code execution on your servers. CISA has ordered federal agencies to patch by April 30, signaling the severity of this threat.

KelpDAO Hack: $290M Crypto Heist Hits DeFi Protocols
North Korean state hackers allegedly stole $290 million from KelpDAO by exploiting cross-chain verification systems. The attack forced major lending protocols including Aave to freeze operations, raising urgent questions about DeFi security for institutional investors.

Seiko USA Breach 2026: What E-Commerce Leaders Must Know
The Seiko USA website defacement exposes critical vulnerabilities in Shopify-based retail operations. This attack demonstrates how threat actors are increasingly targeting brand-name companies through their e-commerce platforms, with potential customer data exposure and ransom demands creating both financial and reputational risks for businesses of all sizes.



