Microsoft has confirmed active exploitation of a zero-day vulnerability in on-premises Exchange Server. The flaw, tracked as CVE-2026-42897, allows attackers to execute arbitrary JavaScript in a victim's browser by sending a crafted email. No permanent patch is available yet.
Zero-day XSS flaw in OWA
The vulnerability is a cross-site scripting issue in the Outlook Web Access component, rated CVSS 8.1. It affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition at any update level. Exchange Online is not vulnerable.
Microsoft deployed an emergency mitigation on May 14 through the Exchange Emergency Mitigation Service, labeled M2.1.x. The mitigation disables the OWA Print Calendar feature, inline images, and the OWA Light interface. CISA added the flaw to its Known Exploited Vulnerabilities catalog on May 15 and requires federal agencies to remediate by May 29.
Microsoft is developing a permanent fix but has not confirmed a release timeline. The company has not identified the threat actors behind the attacks or disclosed which organizations were targeted.
Source: NotebookCheck




Discussion
0 comments