Summary
Microsoft has confirmed that a high-severity zero-day vulnerability in Exchange Server, tracked as CVE-2026-42897, is being actively exploited in the wild. The flaw is a cross-site scripting (XSS) vulnerability that allows arbitrary JavaScript execution in the browser context when a user opens a specially crafted email in Outlook Web Access (OWA).
The vulnerability affects on-premises Exchange Server Subscription Edition RTM, Exchange Server 2019, and Exchange Server 2016. Exchange Online is not impacted. A permanent patch is still under development, but Microsoft has released temporary mitigations via the Exchange Emergency Mitigation Service (EEMS) and the Exchange On-premises Mitigation Tool (EOMT).
CISA has added CVE-2026-42897 to its Known Exploited Vulnerabilities Catalog, ordering Federal Civilian Executive Branch agencies to apply mitigations by May 29, 2026.
Sources
- BleepingComputer — Microsoft Warns of Exchange Zero-Day
- The Hacker News — On-Prem Microsoft Exchange Server CVE
- Help Net Security — Exchange Server CVE-2026-42897 Exploited
Commentary
Another day, another Exchange Server zero-day — and this time attackers don’t even need the victim to click a link. Just opening a malicious email in OWA is enough. Given the massive installed base of on-prem Exchange servers, especially in government and enterprise environments still dragging their feet on cloud migration, the attack surface here is enormous.
The fact that Microsoft has no permanent fix yet — only temporary mitigations — makes this particularly urgent. If you’re running on-prem Exchange, verify that EEMS is enabled immediately. CISA’s May 29 deadline sends a clear signal: this is a serious, actively weaponized flaw. Don’t wait for Patch Tuesday.
