logo

Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers

ID: a2688a28-6372-5cd6-b121-867c84ede673

STIX ID: report--a2688a28-6372-5cd6-b121-867c84ede673

Feed Name: securityonline.info

Threat Score
86/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Ddos

...
...

Microsoft warns of CVE-2026-42897, a high-severity Outlook Web Access vulnerability (CVSS 8.1) being actively exploited that allows arbitrary JavaScript execution via specially crafted emails in the browser context; on-premises Exchange Server 2016, 2019 and Subscription Edition are affected. Microsoft has deployed emergency mitigations via the EM Service (automatically enabled for most environments) and provides a manual Exchange on‑premises Mitigation Tool (EOMT) for air-gapped systems while a permanent patch is developed, though permanent updates for older servers require enrollment in Period 2 ESU.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.