Skip to content
CC-4785 - Microsoft Releases Security Advisory for a Zero

CC-4785 - Microsoft Releases Security Advisory for a Zero

Digital.Nhs.Uk [email protected] (NHS Digital) May 15, 2026

Successful exploitation of CVE‑2026‑42897 could lead to arbitrary JavaScript execution in the browser context for users of on‑premises Microsoft Exchange Server deployments

Successful exploitation of CVE‑2026‑42897 could lead to arbitrary JavaScript execution in the browser context for users of on‑premises Microsoft Exchange Server deployments

The following platforms are known to be affected:

Microsoft Exchange Server

Note: Exchange Online is not impacted by this vulnerability.

Exploitation of CVE-2026-42897

Microsoft has confirmed active exploitation of CVE-2026-42897 in the wild.

The NHS England National CSOC assesses further exploitation as highly likely.

Microsoft has released a security advisory to address a high‑severity vulnerability in Microsoft Exchange Server. An attacker could exploit this vulnerability by sending a specially crafted email to a user. If the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context..

Affected organisations are encouraged to review Microsoft's Addressing Exchange Server May 2026 vulnerability CVE‑2026‑42897 and Microsoft Exchange Server Spoofing Vulnerability advisories and follow relevant mitigation steps as soon as possible.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Last edited: 15 May 2026 11:58 am

Extracted Entities