Cross-Site Scripting Vulnerability in Microsoft Exchange Server
CVE-2026-42897
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 14 May 2026
Badges
What is CVE-2026-42897?
CVE-2026-42897 is a cross-site scripting (XSS) vulnerability found in Microsoft Exchange Server, a widely utilized email and calendaring platform for businesses and organizations. This vulnerability arises from the improper handling of user inputs during the generation of web pages, allowing unauthorized attackers to inject malicious scripts into web pages viewed by other users. The impact of such exploitation can be severe, as it enables attackers to perform spoofing attacks within the network, which can mislead users and compromise sensitive information. Specifically, attackers could gain the ability to mimic legitimate users, potentially resulting in unauthorized access to sensitive communications or data.
Potential impact of CVE-2026-42897
-
Spoofing Attacks: Unauthorized attackers can impersonate legitimate users, leading to potential misinformation and manipulation of user actions, which can compromise data integrity and trust within the organization.
-
Data Leakage: There is a risk of sensitive information being captured by the malicious scripts injected through the vulnerability, which can lead to data breaches and exploitation of confidential data.
-
User Distrust: Exploitation of this vulnerability can create a climate of distrust among users, as they might be skeptical about the authenticity of communications and transactions within the Exchange Server platform, damaging the reputation of the organization.
CISA has reported CVE-2026-42897
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-42897 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.
The CISA's recommendation is: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected Version(s)
Microsoft Exchange Server 2016 Cumulative Update 23 x64-based Systems 15.01.0.0 < 15.01.2507.069
Microsoft Exchange Server 2019 Cumulative Update 14 x64-based Systems 15.02.0.0 < 15.02.1544.041
Microsoft Exchange Server 2019 Cumulative Update 15 x64-based Systems 15.02.0.0 < 15.02.1748.046
News Articles
CTO at NCSC Summary: week ending August 2nd
A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery...
1 week ago
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Russian hackers exploit CVE-2026-42897 in OWA to deploy OWAReaper, a browser implant that persists through credential rotation and device re-imaging.
2 weeks ago
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper.
2 weeks ago
References
EPSS Score
70% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 💰
Used in Ransomware
- 👾
Exploit known to exist
- 🦅
CISA Reported
- 📰
First article discovered by Securityweek
- 📈
Vulnerability started trending
Vulnerability published
Vulnerability Reserved