CVE-2026-42897
published 2026-05-14CVE-2026-42897: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform…
PriorityP179medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-05-29
Exploited in the wild
EPSS
5.64%
92.0th percentile
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandGet-ExchangeServer | Where-Object { $_.ServerRole -ne "Edge" } | .\EOMT.ps1 -CVE "CVE-2026-42897"↗
- →Monitor for crafted emails opened in Outlook Web Access (OWA) that trigger arbitrary JavaScript execution in the browser context — the attack vector is a malicious email opened via OWA under certain interaction conditions. ↗
- →The Exchange Emergency Mitigation Service applies a URL rewrite configuration automatically; alert on any tampering with or disabling of this Windows service, as it is the primary temporary mitigation for CVE-2026-42897. ↗
- →Scope detection to on-premises Exchange Server 2016, 2019, and SE (any update level); Exchange Online is confirmed not affected and should be excluded from alerting. ↗
- →CISA added CVE-2026-42897 to its KEV catalog on May 15, 2026, confirming active in-the-wild exploitation; treat any unpatched on-prem Exchange server as actively targeted. ↗
- ·The mitigation status message 'Mitigation invalid for this exchange version.' in the Description field is cosmetic only — the mitigation still applies successfully if the Status field shows 'Applied'; do not treat this message as a mitigation failure. ↗
- ·Microsoft recommends keeping the URL rewrite mitigation in place even after applying the June 2026 Security Updates, as it provides an additional layer of defense. ↗
- ·For air-gapped environments where the Exchange Emergency Mitigation Service cannot reach the internet, the manual EOMT.ps1 script must be used instead of the automatic mitigation service. ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vulncheck8.1HIGH
cisa6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Exchange Server cross site scripting
vuldb·2026-05-14·CVSS 8.1
CVE-2026-42897 [HIGH] Microsoft Exchange Server cross site scripting
A vulnerability, which was classified as problematic, has been found in Microsoft Exchange Server. The impacted element is an unknown function. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2026-42897. The attack can be initiated remotely. There is not any exploit available.
GHSA
GHSA-3c39-338m-m4vp: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to p
ghsa_unreviewed·2026-05-14
CVE-2026-42897 [HIGH] CWE-79 GHSA-3c39-338m-m4vp: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to p
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
VulnCheck
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
vulncheck·2026·CVSS 8.1
CVE-2026-42897 [HIGH] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-May
CISA
Microsoft Exchange Server Cross-Site Scripting Vulnerability
cisa·2026-05-15·CVSS 6.1
CVE-2026-42897 [MEDIUM] CWE-79 Microsoft Exchange Server Cross-Site Scripting Vulnerability
Vulnerability: Microsoft Exchange Server Cross-Site Scripting Vulnerability
Affected: Microsoft Microsoft
Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897 ; https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service ; https://nvd.nist.gov/vuln/detail/CVE-2026-4289
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft patches Exchange Server zero-day exploited in attacks
blogs_bleepingcomputer·2026-06-10·CVSS 6.1
CVE-2026-42897 [MEDIUM] Microsoft patches Exchange Server zero-day exploited in attacks
## Microsoft patches Exchange Server zero-day exploited in attacks
## Sergiu Gatlan
BleepingComputer has yet to receive a response from Microsoft to questions about the attacks exploiting CVE-2026-42897.
Yesterday, Microsoft released security updates to address the security flaw in affected Exchange Server installations, advising admins to deploy them "as soon as possible" and leave the mitigations in place for additional protection.
"Microsoft recommends installing the June 2026 Security Updates for your version of Exchange Server as soon as possible to be protected from this vulnerability," it noted in an update to the original security advisory.
"As part of our ongoing efforts to strengthen security and improve defenses across environments, we continue to enhance protections for cr
Hackernews
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
blogs_hackernews·2026-05-21·CVSS 7.8
CVE-2026-41091 [HIGH] Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild.
The former, tracked as CVE-2026-41091 , is rated 7.8 on the CVSS scoring system. Successful exploitation of the flaw could allow an attacker to gain SYSTEM privileges.
"Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally," Microsoft said in an advisory.
The second vulnerability under exploitation is CVE-2026-45498 (CVSS score:
Hackernews
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
blogs_hackernews·2026-05-18·CVSS 6.1
CVE-2026-42897 [MEDIUM] ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted.
The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production incident. AI is speeding up vulnerability discovery, attackers are moving quickly, and old exposure still keeps paying off.
Patch the quiet risks first. Let’s g
Hackernews
On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
blogs_hackernews·2026-05-15·CVSS 6.1
CVE-2026-42897 [MEDIUM] On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue.
"Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoof
2026-05-14
Published
2026-05-15
Added to CISA KEV
Exploited in the wild