logo

Unpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897)

ID: aca0c389-efa9-5979-9459-110f646d9784

STIX ID: report--aca0c389-efa9-5979-9459-110f646d9784

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Zeljka Zorz

...
...

Microsoft warns that CVE-2026-42897, a critical cross-site scripting (XSS) vulnerability in on-premises Microsoft Exchange Server (Subscription Edition RTM, 2019, and 2016), is being actively exploited via specially crafted emails opened in Outlook Web Access; Microsoft has published temporary mitigations and plans security updates for affected Exchange builds while Exchange Online is not affected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.