logo

CVE-2026-42897: Exchange Server OWA Spoofing Flaw Exploited via Crafted Email

ID: 5143a950-d255-5603-a3ec-39012c7bfa11

STIX ID: report--5143a950-d255-5603-a3ec-39012c7bfa11

Feed Name: SOC Prime Blog

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: SOC Prime Team

...
...

Microsoft disclosed CVE-2026-42897, an 8.1 CVSS XSS/spoofing vulnerability in on-premises Exchange Server OWA (2016, 2019, Subscription Edition) that can execute arbitrary JavaScript from a crafted email; exploitation in the wild has been observed, Exchange Online is not affected, and Microsoft recommends using the Exchange Emergency Mitigation Service or the Exchange On‑premises Mitigation Tool until a permanent patch is released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.