Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Home/CyberSecurity News/Critical Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks
CyberSecurity News

Critical Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks

Key Takeaways A critical zero-day spoofing vulnerability, CVE-2026-42897, has been identified in on-premises Microsoft Exchange Server instances. This flaw is under active exploitation, allowing...

Emy Elsamnoudy
Emy Elsamnoudy
June 11, 2026 4 Min Read
52 0

Key Takeaways

  • A critical zero-day spoofing vulnerability, CVE-2026-42897, has been identified in on-premises Microsoft Exchange Server instances.
  • This flaw is under active exploitation, allowing attackers to execute arbitrary JavaScript in Outlook Web Access (OWA) via specially crafted emails.
  • Affected versions include all update levels of Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE); Exchange Online is not impacted.
  • Microsoft has released Security Updates (SUs) on June 9, 2026, to permanently fix the issue, alongside temporary mitigations via the Exchange Emergency Mitigation (EM) Service or Exchange On-Premises Mitigation Tool (EOMT).

Microsoft Exchange Server Zero-Day Under Active Exploitation

Microsoft has confirmed that a critical zero-day spoofing vulnerability, tracked as CVE-2026-42897, is currently being exploited in attacks targeting on-premises Exchange Server deployments. This serious flaw enables threat actors to execute arbitrary JavaScript within Outlook Web Access (OWA) sessions simply by sending a malicious email that a user opens in their browser.

Table Of Content

  • Key Takeaways
  • Microsoft Exchange Server Zero-Day Under Active Exploitation
  • Impact and Scope of CVE-2026-42897
  • Mitigation and Permanent Fixes
  • What You Should Do

The vulnerability, publicly disclosed by Microsoft on May 14, 2026, is categorized as a cross-site scripting (XSS) bug (CWE-79). It arises from inadequate sanitization of user input during the generation of web pages within Exchange Outlook Web Access. An unauthenticated attacker can craft and send a specific email. If a target opens this email in OWA and certain interaction conditions are met, the attacker-supplied JavaScript will execute within the browser context of the logged-in user.

Impact and Scope of CVE-2026-42897

Microsoft’s assessment classifies CVE-2026-42897 with an “Exploitation Detected” status, underscoring that active attacks are already leveraging this weakness. The vulnerability carries a Critical CVSS v3.1 base score of 8.1. This high severity reflects that the attack can be launched over a network, requires no special privileges from the attacker, and only demands basic user interaction, specifically opening an email in OWA.

Successful exploitation of this flaw can lead to significant consequences, including email spoofing, theft of credentials, session hijacking, and the ability for the attacker to perform actions on behalf of the compromised user within their browser session. The nature of the attack, delivered via email and triggered upon content rendering in OWA, allows it to bypass security controls typically focused on attachments or links, potentially blending seamlessly into normal mailbox activity.

The vulnerability impacts all supported versions of Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE). Importantly, Microsoft has confirmed that Exchange Online (Microsoft 365) is not affected. Furthermore, exploitation has only been observed through OWA rendering, with no known impact on Exchange Online or other non-OWA access methods.

Mitigation and Permanent Fixes

As an immediate defense, Microsoft implemented mitigation M2.1.x for CVE-2026-42897 via the Exchange Emergency Mitigation (EM) Service. This service is enabled by default on supported on-premises Exchange servers and automatically deploys the necessary protections. Organizations can verify the application of this mitigation using the EM “Viewing Applied Mitigations” guidance or by running the Exchange Health Checker script, which includes an EEMS check section in its HTML report.

For environments that are disconnected or air-gapped, Microsoft provides the Exchange On-Premises Mitigation Tool (EOMT). This tool applies CVE-specific mitigations per server using a PowerShell script, PowerShell.ps1, with the CVE parameter.

It is crucial to note that these temporary mitigations rely on browser Content Security Policy (CSP). Therefore, they do not offer protection to users accessing OWA via Internet Explorer or Edge in Internet Explorer Mode, as these browsers lack comprehensive CSP support.

On June 9, 2026, Microsoft released permanent Security Updates (SUs) to address CVE-2026-42897. These updates are available for Exchange SE RTM, Exchange Server 2019 CU14/CU15, and Exchange Server 2016 CU23. However, the updates for Exchange Server 2016 and 2019 are exclusively available to customers enrolled in the Period 2 Extended Security Update (ESU) program.

Microsoft advises installing the June 2026 SUs as quickly as possible. Even after patching, organizations are recommended to keep the CVE-2026-42897 mitigation in place as an additional layer of defense.

Applying the mitigation, whether through the EM Service or EOMT, may temporarily affect or degrade certain OWA functionalities. These include calendar printing, inline image display in the reading pane, OWA Light, published calendars, and the OWACalendar proxy health set, potentially triggering false alerts in monitoring systems. These issues are expected to resolve once the June 2026 update is installed, after which organizations can manually remove the mitigation if they choose.

Microsoft also emphasized in its June 2026 blog that the EM and feature flighting services will cease consuming new configuration files from July 2026 unless Exchange servers are updated to at least the June 2026 level. This further reinforces the urgency of migrating to current builds. For organizations still operating Exchange 2016/2019 without Period 2 ESU, Microsoft recommends migrating to Exchange SE to ensure continued access to future security fixes.

What You Should Do

  • Apply Security Updates (SUs): Install the June 2026 Security Updates for Exchange SE RTM, Exchange Server 2019 CU14/CU15, and Exchange Server 2016 CU23 immediately. Note that 2016/2019 updates require Period 2 Extended Security Update (ESU) enrollment.
  • Verify EM Service Mitigation: Ensure the Exchange Emergency Mitigation (EM) Service is active and has deployed mitigation M2.1.x for CVE-2026-42897. Use the EM “Viewing Applied Mitigations” guidance or the Exchange Health Checker script.
  • Utilize EOMT for Disconnected Environments: For air-gapped Exchange servers, deploy mitigations using the Exchange On-Premises Mitigation Tool (EOMT) via the provided PowerShell script.
  • Maintain Mitigation Post-Patch: Keep the CVE-2026-42897 mitigation in place even after installing the June 2026 SUs as an added defensive measure.
  • Avoid Unsupported Browsers: Inform users that temporary mitigations do not protect OWA access via Internet Explorer or Edge in Internet Explorer Mode due to lack of CSP support.
  • Plan for Migration: If running Exchange 2016/2019 without Period 2 ESU, plan to migrate to Exchange SE to ensure future security support.
  • Update Regularly: Ensure Exchange servers are updated to at least the June 2026 level to ensure continued consumption of new configuration files by EM and feature flighting services from July 2026 onwards.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Ivanti EPMM CVE-2023-35078 Lets Attackers Run Remote Code

Next Post

China-Linked JDY Botnet Exploits SOHO, IoT Devices

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us