logo

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

ID: 0fbd1935-a4a4-5354-abe9-9bfb3bbe9ef8

STIX ID: report--0fbd1935-a4a4-5354-abe9-9bfb3bbe9ef8

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: [email protected] (The Hacker News)

...
...

Microsoft disclosed CVE-2026-42897, a cross-site scripting (XSS) spoofing vulnerability in on‑premises Exchange Server (2016, 2019, Subscription Edition) with a CVSS of 8.1 and an "Exploitation Detected" assessment; the flaw can allow arbitrary JavaScript execution in Outlook Web Access when a crafted email is opened, and Microsoft has provided temporary mitigations via the Exchange Emergency Mitigation Service and the Exchange on‑premises Mitigation Tool while a permanent fix is prepared.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.