Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
ID: a2688a28-6372-5cd6-b121-867c84ede673
STIX ID: report--a2688a28-6372-5cd6-b121-867c84ede673
Feed Name: securityonline.info
Microsoft warns of CVE-2026-42897, a high-severity Outlook Web Access vulnerability (CVSS 8.1) being actively exploited that allows arbitrary JavaScript execution via specially crafted emails in the browser context; on-premises Exchange Server 2016, 2019 and Subscription Edition are affected. Microsoft has deployed emergency mitigations via the EM Service (automatically enabled for most environments) and provides a manual Exchange on‑premises Mitigation Tool (EOMT) for air-gapped systems while a permanent patch is developed, though permanent updates for older servers require enrollment in Period 2 ESU.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
