cbcvebase.
CVE-2026-42897
published 2026-05-14

CVE-2026-42897: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform…

PriorityP179medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-05-29
Exploited in the wild
EPSS
5.64%
92.0th percentile
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server

Detection & IOCsextracted from sources · hover to see the quote

urlaka[.]ms/UnifiedEOMT
command.\EOMT.ps1 -CVE "CVE-2026-42897"
commandGet-ExchangeServer | Where-Object { $_.ServerRole -ne "Edge" } | .\EOMT.ps1 -CVE "CVE-2026-42897"
  • Monitor for crafted emails opened in Outlook Web Access (OWA) that trigger arbitrary JavaScript execution in the browser context — the attack vector is a malicious email opened via OWA under certain interaction conditions.
  • The Exchange Emergency Mitigation Service applies a URL rewrite configuration automatically; alert on any tampering with or disabling of this Windows service, as it is the primary temporary mitigation for CVE-2026-42897.
  • Scope detection to on-premises Exchange Server 2016, 2019, and SE (any update level); Exchange Online is confirmed not affected and should be excluded from alerting.
  • CISA added CVE-2026-42897 to its KEV catalog on May 15, 2026, confirming active in-the-wild exploitation; treat any unpatched on-prem Exchange server as actively targeted.
  • ·The mitigation status message 'Mitigation invalid for this exchange version.' in the Description field is cosmetic only — the mitigation still applies successfully if the Status field shows 'Applied'; do not treat this message as a mitigation failure.
  • ·Microsoft recommends keeping the URL rewrite mitigation in place even after applying the June 2026 Security Updates, as it provides an additional layer of defense.
  • ·For air-gapped environments where the Exchange Emergency Mitigation Service cannot reach the internet, the manual EOMT.ps1 script must be used instead of the automatic mitigation service.

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vulncheck8.1HIGH
cisa6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.