FSR Onimusha: Way of the Sword Steam Deck Performance Guide NINTENDO SWITCH 2 Digimon Story: Time Stranger DLC ‘A Hero’s Eternal Legacy’ Announced PLAYSTATION 5 Cygames Launches Where the Seeds Fall for PS5, Switch 2, and PC PLAYSTATION 5 Dragon Ball Xenoverse 3 Trailer Reveals New Android Avatar Race PLAYSTATION 5 Uncanyon Puzzle Adventure Announced for PS5, Xbox Series, Switch 2, and PC NINTENDO Final Fantasy Resonance Demo Now Live With Save Carryover HANDHELD GAMING FunnyPlaying Retro Pixel MiniGB Brings Game Boy Cartridges to a 2.6-Inch Handheld CONSOLES LEGO PlayStation Set Ships October 4 for $180 With Opening Disc Drive NINTENDO SWITCH How To Fish Console Availability: PS5, Xbox Series X|S, and Switch DLSS NVIDIA DLSS Multi Frame Generation Mod Brings Blackwell Tech to RTX 40 Series GAMES Killing Floor 3 Update 2.017 Fixes Stuttering and Buffs Damage PC HARDWARE Acer EP130K ePaper Monitor: 13.3-inch 3.2K Display Ships in 2027 AYANEO MSI Claw 8 EX AI+ Gets $1,499 Price Cut With Arc B370 GPU GAMES GTA 6 Miami Marketing Blocked by Sheriff Over Crime Stereotypes

Microsoft Exchange Server Zero-Day CVE-2026-42897 Exploited via Crafted Email

Owen Carter 1 min read

Microsoft confirms active exploitation of CVE-2026-42897, a zero-day XSS vulnerability in on-premises Exchange Server. Emergency mitigation deployed; no permanent patch yet. CISA adds to KEV catalog.

Microsoft Exchange Server Zero-Day CVE-2026-42897 Exploited via Crafted Email
SOFTWARE AND UPDATES

Microsoft has confirmed active exploitation of a zero-day vulnerability in on-premises Exchange Server. The flaw, tracked as CVE-2026-42897, allows attackers to execute arbitrary JavaScript in a victim's browser by sending a crafted email. No permanent patch is available yet.

Zero-day XSS flaw in OWA

The vulnerability is a cross-site scripting issue in the Outlook Web Access component, rated CVSS 8.1. It affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition at any update level. Exchange Online is not vulnerable.

Microsoft deployed an emergency mitigation on May 14 through the Exchange Emergency Mitigation Service, labeled M2.1.x. The mitigation disables the OWA Print Calendar feature, inline images, and the OWA Light interface. CISA added the flaw to its Known Exploited Vulnerabilities catalog on May 15 and requires federal agencies to remediate by May 29.

Microsoft is developing a permanent fix but has not confirmed a release timeline. The company has not identified the threat actors behind the attacks or disclosed which organizations were targeted.

Source: NotebookCheck