Exchange Server XSS Flaw Exploited in Wild
A cross-site scripting vulnerability in Microsoft Exchange Server (CVE-2026-42897) is being actively exploited via crafted emails opened in Outlook Web Access.
Microsoft has confirmed active exploitation of CVE-2026-42897, a cross-site scripting vulnerability affecting multiple Microsoft Exchange Server versions including Subscription Edition RTM, 2019 CU14/CU15, and 2016 CU23. The flaw stems from improper neutralization of input during web page generation, allowing an attacker to send a specially crafted email that, when opened in Outlook Web Access under certain interaction conditions, executes arbitrary JavaScript in the victim's browser context with browser-level permissions.
Exploitation could enable data theft, malware installation, or further compromise of the victim's system, since the malicious script inherits the permissions of the browser session. Microsoft has released mitigation guidance and is distributing temporary protections through the Exchange Emergency Mitigation Service while a full patch process is finalized. Given Exchange Server's widespread enterprise use and the confirmed in-the-wild exploitation, organizations running affected versions should prioritize applying Microsoft's mitigations immediately.
MS-ISAC recommends standard vulnerability management practices including prompt patching, DNS/URL filtering, restriction of web-based content and JavaScript execution where feasible, and network intrusion detection/prevention to reduce exposure while remediation is completed.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-microsoft-exchange-server-could-allow-for-arbitrary-code-execution_2026-050
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free