CISA Warns of Critical Microsoft Exchange Server Vulnerability Exploited in Attacks
Key Takeaways A critical cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Microsoft Exchange Server’s Outlook Web Access (OWA) is actively being exploited in real-world attacks. The...
Key Takeaways
- A critical cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Microsoft Exchange Server’s Outlook Web Access (OWA) is actively being exploited in real-world attacks.
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch by May 29, 2026.
- This XSS flaw allows attackers to execute arbitrary JavaScript, potentially leading to session hijacking, credential theft, and further system compromise.
- Organizations running on-premises Microsoft Exchange Servers are urged to apply vendor-provided mitigations and security updates immediately, or implement alternative protective measures.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding active exploitation of a newly identified vulnerability within Microsoft Exchange Server. This critical flaw poses a significant risk to organizations maintaining on-premises email infrastructure, as threat actors are already leveraging it in ongoing attacks.
Table Of Content
Designated as CVE-2026-42897, the vulnerability is a cross-site scripting (XSS) defect specifically impacting Microsoft Exchange Server’s Outlook Web Access (OWA) component.
According to Microsoft’s official advisory, the flaw arises during the generation of web pages and can be triggered under specific user interaction conditions. Successful exploitation enables attackers to execute arbitrary JavaScript code within a victim’s web browser session.
CISA officially added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on May 15, 2026, confirming its active exploitation in the wild. This listing mandates that all federal agencies and organizations operating under Binding Operational Directive (BOD) 22-01 must remediate the issue by May 29, 2026.
Understanding the Microsoft Exchange Server Vulnerability
Cybersecurity experts emphasize that XSS vulnerabilities in enterprise email platforms like Exchange are particularly dangerous. These flaws can be weaponized to hijack authenticated user sessions, providing a critical foothold for attackers.
In a typical attack scenario, a malicious actor could craft a specialized link and trick a user into clicking it. This action would then execute unauthorized scripts within the user’s active browser session, potentially leading to the compromise of credentials, unauthorized access to mailboxes, or a deeper intrusion into the corporate network.
While Microsoft has not publicly linked CVE-2026-42897 to specific ransomware campaigns, its inclusion in CISA’s KEV catalog strongly indicates that various threat actors are actively interested in and exploiting this vulnerability. Exchange servers have historically been prime targets for cybercriminals due to their central role in managing sensitive communications, user identities, and credentials.
The vulnerability falls under CWE-79, a common classification for web security flaws characterized by improper neutralization of input during the generation of web pages. Despite being a well-understood type of vulnerability, XSS continues to be widely exploited due to inconsistent input validation practices and the inherent complexity of modern web applications.
What You Should Do
- Apply Patches Immediately: Organizations should prioritize applying all vendor-provided security updates and mitigations for Microsoft Exchange Server without delay.
- Implement Alternative Mitigations: If patches are not yet available or cannot be applied immediately, follow alternative mitigation strategies outlined by Microsoft. Consider temporarily discontinuing the use of affected systems until they can be adequately secured.
- Monitor for Suspicious Activity: Security teams must actively monitor Exchange server logs for any unusual activity, including unexpected script execution, abnormal user behavior in Outlook Web Access sessions, or unusual authentication patterns.
- Review Internet-Facing Exposure: Assess and reduce the exposure of internet-facing Exchange services to minimize the attack surface.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.