Critical Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks
Key Takeaways A critical zero-day spoofing vulnerability, CVE-2026-42897, has been identified in on-premises Microsoft Exchange Server instances. This flaw is under active exploitation, allowing...
Key Takeaways
- A critical zero-day spoofing vulnerability, CVE-2026-42897, has been identified in on-premises Microsoft Exchange Server instances.
- This flaw is under active exploitation, allowing attackers to execute arbitrary JavaScript in Outlook Web Access (OWA) via specially crafted emails.
- Affected versions include all update levels of Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE); Exchange Online is not impacted.
- Microsoft has released Security Updates (SUs) on June 9, 2026, to permanently fix the issue, alongside temporary mitigations via the Exchange Emergency Mitigation (EM) Service or Exchange On-Premises Mitigation Tool (EOMT).
Microsoft Exchange Server Zero-Day Under Active Exploitation
Microsoft has confirmed that a critical zero-day spoofing vulnerability, tracked as CVE-2026-42897, is currently being exploited in attacks targeting on-premises Exchange Server deployments. This serious flaw enables threat actors to execute arbitrary JavaScript within Outlook Web Access (OWA) sessions simply by sending a malicious email that a user opens in their browser.
Table Of Content
The vulnerability, publicly disclosed by Microsoft on May 14, 2026, is categorized as a cross-site scripting (XSS) bug (CWE-79). It arises from inadequate sanitization of user input during the generation of web pages within Exchange Outlook Web Access. An unauthenticated attacker can craft and send a specific email. If a target opens this email in OWA and certain interaction conditions are met, the attacker-supplied JavaScript will execute within the browser context of the logged-in user.
Impact and Scope of CVE-2026-42897
Microsoft’s assessment classifies CVE-2026-42897 with an “Exploitation Detected” status, underscoring that active attacks are already leveraging this weakness. The vulnerability carries a Critical CVSS v3.1 base score of 8.1. This high severity reflects that the attack can be launched over a network, requires no special privileges from the attacker, and only demands basic user interaction, specifically opening an email in OWA.
Successful exploitation of this flaw can lead to significant consequences, including email spoofing, theft of credentials, session hijacking, and the ability for the attacker to perform actions on behalf of the compromised user within their browser session. The nature of the attack, delivered via email and triggered upon content rendering in OWA, allows it to bypass security controls typically focused on attachments or links, potentially blending seamlessly into normal mailbox activity.
The vulnerability impacts all supported versions of Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE). Importantly, Microsoft has confirmed that Exchange Online (Microsoft 365) is not affected. Furthermore, exploitation has only been observed through OWA rendering, with no known impact on Exchange Online or other non-OWA access methods.
Mitigation and Permanent Fixes
As an immediate defense, Microsoft implemented mitigation M2.1.x for CVE-2026-42897 via the Exchange Emergency Mitigation (EM) Service. This service is enabled by default on supported on-premises Exchange servers and automatically deploys the necessary protections. Organizations can verify the application of this mitigation using the EM “Viewing Applied Mitigations” guidance or by running the Exchange Health Checker script, which includes an EEMS check section in its HTML report.
For environments that are disconnected or air-gapped, Microsoft provides the Exchange On-Premises Mitigation Tool (EOMT). This tool applies CVE-specific mitigations per server using a PowerShell script, PowerShell.ps1, with the CVE parameter.
It is crucial to note that these temporary mitigations rely on browser Content Security Policy (CSP). Therefore, they do not offer protection to users accessing OWA via Internet Explorer or Edge in Internet Explorer Mode, as these browsers lack comprehensive CSP support.
On June 9, 2026, Microsoft released permanent Security Updates (SUs) to address CVE-2026-42897. These updates are available for Exchange SE RTM, Exchange Server 2019 CU14/CU15, and Exchange Server 2016 CU23. However, the updates for Exchange Server 2016 and 2019 are exclusively available to customers enrolled in the Period 2 Extended Security Update (ESU) program.
Microsoft advises installing the June 2026 SUs as quickly as possible. Even after patching, organizations are recommended to keep the CVE-2026-42897 mitigation in place as an additional layer of defense.
Applying the mitigation, whether through the EM Service or EOMT, may temporarily affect or degrade certain OWA functionalities. These include calendar printing, inline image display in the reading pane, OWA Light, published calendars, and the OWACalendar proxy health set, potentially triggering false alerts in monitoring systems. These issues are expected to resolve once the June 2026 update is installed, after which organizations can manually remove the mitigation if they choose.
Microsoft also emphasized in its June 2026 blog that the EM and feature flighting services will cease consuming new configuration files from July 2026 unless Exchange servers are updated to at least the June 2026 level. This further reinforces the urgency of migrating to current builds. For organizations still operating Exchange 2016/2019 without Period 2 ESU, Microsoft recommends migrating to Exchange SE to ensure continued access to future security fixes.
What You Should Do
- Apply Security Updates (SUs): Install the June 2026 Security Updates for Exchange SE RTM, Exchange Server 2019 CU14/CU15, and Exchange Server 2016 CU23 immediately. Note that 2016/2019 updates require Period 2 Extended Security Update (ESU) enrollment.
- Verify EM Service Mitigation: Ensure the Exchange Emergency Mitigation (EM) Service is active and has deployed mitigation M2.1.x for CVE-2026-42897. Use the EM “Viewing Applied Mitigations” guidance or the Exchange Health Checker script.
- Utilize EOMT for Disconnected Environments: For air-gapped Exchange servers, deploy mitigations using the Exchange On-Premises Mitigation Tool (EOMT) via the provided PowerShell script.
- Maintain Mitigation Post-Patch: Keep the CVE-2026-42897 mitigation in place even after installing the June 2026 SUs as an added defensive measure.
- Avoid Unsupported Browsers: Inform users that temporary mitigations do not protect OWA access via Internet Explorer or Edge in Internet Explorer Mode due to lack of CSP support.
- Plan for Migration: If running Exchange 2016/2019 without Period 2 ESU, plan to migrate to Exchange SE to ensure future security support.
- Update Regularly: Ensure Exchange servers are updated to at least the June 2026 level to ensure continued consumption of new configuration files by EM and feature flighting services from July 2026 onwards.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.