VORANT. Threat Intelligence Sign in Get the full feed

Exchange Server XSS Flaw Exploited in Wild

high vulnerability government-nationaltechnology

A cross-site scripting vulnerability in Microsoft Exchange Server (CVE-2026-42897) is being actively exploited via crafted emails opened in Outlook Web Access.

Microsoft has confirmed active exploitation of CVE-2026-42897, a cross-site scripting vulnerability affecting multiple Microsoft Exchange Server versions including Subscription Edition RTM, 2019 CU14/CU15, and 2016 CU23. The flaw stems from improper neutralization of input during web page generation, allowing an attacker to send a specially crafted email that, when opened in Outlook Web Access under certain interaction conditions, executes arbitrary JavaScript in the victim's browser context with browser-level permissions.

Exploitation could enable data theft, malware installation, or further compromise of the victim's system, since the malicious script inherits the permissions of the browser session. Microsoft has released mitigation guidance and is distributing temporary protections through the Exchange Emergency Mitigation Service while a full patch process is finalized. Given Exchange Server's widespread enterprise use and the confirmed in-the-wild exploitation, organizations running affected versions should prioritize applying Microsoft's mitigations immediately.

MS-ISAC recommends standard vulnerability management practices including prompt patching, DNS/URL filtering, restriction of web-based content and JavaScript execution where feasible, and network intrusion detection/prevention to reduce exposure while remediation is completed.

Mentioned in this report

Vulnerabilities CVE-2026-42897KEV

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-microsoft-exchange-server-could-allow-for-arbitrary-code-execution_2026-050

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free