Skip to content

Microsoft Exchange Server Zero-Day CVE-2026-42897 Actively Exploited in XSS Attacks — OOB Mitigation Available, No Patch Yet

Microsoft disclosed an actively exploited cross-site scripting zero-day in Exchange Server (CVE-2026-42897) that allows attackers to inject malicious scripts into Outlook Web App sessions, hijack authenticated user sessions, and exfiltrate email content. No patch is available. Microsoft deployed an Emergency Exchange Mitigation Service (EEMS) rule as an interim control while a patch is developed.

Article network-security

Microsoft confirmed on 15 May that CVE-2026-42897 — a cross-site scripting vulnerability in Exchange Server’s Outlook Web App — is being actively exploited in targeted attacks. The zero-day allows an attacker to inject malicious JavaScript into an authenticated OWA session, enabling session token hijacking, email exfiltration, and potential lateral movement via Exchange impersonation. No patch is currently available. Microsoft has deployed a mitigating rule via the Exchange Emergency Mitigation Service (EEMS) and CISA has added the vulnerability to the Known Exploited Vulnerabilities catalogue.

Technical Detail

The vulnerability exists in Exchange Server’s rendering of certain message header fields in Outlook Web App. When a user opens a specifically crafted email in OWA, Exchange fails to properly sanitise a header field value that is reflected in the OWA interface, resulting in the execution of attacker-controlled JavaScript in the context of the victim’s OWA session.

The attacker’s JavaScript can:

  • Extract the victim’s OWA session cookie and transmit it to an attacker-controlled server, enabling session hijacking without password theft
  • Silently forward email content and attachments to attacker-controlled email addresses
  • Use Exchange’s MAPI-over-HTTP API with the session token to search and exfiltrate mailbox contents
  • Trigger searches across the user’s entire mailbox, potentially recovering sensitive communications, credentials shared via email, or internal documents

The attack requires sending a specially crafted email to a target whose mailbox is hosted on an on-premises Exchange Server and who opens the email in OWA. Exchange Online (Microsoft 365) is not affected.

Active Exploitation Context

Microsoft’s threat intelligence team identified targeted exploitation of CVE-2026-42897 prior to Microsoft’s own disclosure. Attribution has not been published, but the targeting pattern — focused on government, defence, and financial services sectors — is consistent with nation-state reconnaissance operations interested in email intelligence.

Interim Mitigation

Microsoft deployed an EEMS rule (Emergency Mitigation Service — Exchange Server’s automated threat response mechanism) on 15 May that blocks the specific attack vector through HTTP request pattern matching. EEMS updates are applied automatically to Exchange Servers with EEMS enabled.

To verify EEMS is enabled and the mitigation has applied: Get-ExchangeDiagnosticInfo -Server <ServerName> -Process EdgeTransport -Component RuleUpdateStatus

Additional manual mitigations whilst awaiting a patch:

  • Disable OWA: If OWA is not operationally required, disabling it eliminates the attack surface. Consider directing users to the Outlook desktop client exclusively.
  • Network access controls: Restrict OWA access to known IP ranges or require VPN access before OWA is reachable. This limits attacker ability to interact with the XSS payload.
  • Verify EEMS is active: Confirm the EEMS rule has applied to all Exchange Servers. Servers that have been isolated from internet access for EEMS updates may not have received the mitigation.
  • Enable EEMS if disabled: If EEMS was disabled for any reason, re-enable it to receive the mitigation: Set-ExchangeServer -MitigationsEnabled $true.
  • Hunt for exploitation: Review Exchange and IIS logs for the header pattern identified in Microsoft’s advisory. Look for anomalous OWA session activity — logins from new IPs, mass email access, or unexpected email forwarding rule creation.
  • Patch immediately when available: This is an actively exploited zero-day in widely deployed email infrastructure. Patch upon release without waiting for scheduled maintenance.

Share this article

Related Intelligence

🌐 Network

Cisco Catalyst SD-WAN CVE-2026-20182 CVSS 10.0 Authentication Bypass Exploited as Zero-Day — Attackers Injecting Rogue SD-WAN Devices

Cisco disclosed a CVSS 10.0 authentication bypass in the Catalyst SD-WAN Manager that has been actively exploited as a zero-day, allowing unauthenticated attackers to inject rogue SD-WAN devices into the management plane and intercept or reroute enterprise WAN traffic. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalogue with a 72-hour patching deadline for federal agencies.

#cisco +5
🌐 Network

PAN-OS CVE-2026-0300 — Unauthenticated RCE Zero-Day Actively Exploited in Firewall Espionage Attacks

A critical unauthenticated remote code execution vulnerability in Palo Alto Networks PAN-OS has been under active exploitation since at least early April 2026, linked to espionage-motivated threat actors targeting government and critical infrastructure networks. CVE-2026-0300 affects the User-ID authentication portal on VM-Series and hardware firewalls; CISA added it to the KEV catalogue on 6 May 2026. Patches are available — apply immediately.

#palo-alto +9
🌐 Network

Cisco Catalyst SD-WAN Manager CVE-2026-20262 Actively Exploited — Arbitrary File Overwrite Escalates to Root

A file upload vulnerability in Cisco Catalyst SD-WAN Manager is under active exploitation, allowing an attacker with network-operator level access to overwrite arbitrary files on the underlying operating system and escalate privileges to root. CISA added CVE-2026-20262 to the Known Exploited Vulnerabilities catalogue on 16 June, setting a federal remediation deadline.

#cisco +5