Skip to content
Microsoft patches actively exploited Exchange Server XSS vulnerability

Microsoft patches actively exploited Exchange Server XSS vulnerability

Feeds.4Sysops IT News June 11, 2026

Microsoft has released critical security updates to address CVE-2026-42897, a cross-site scripting vulnerability in Exchange Server that is currently being exploited. The flaw affects Exchange Server 2016, 2019, and the Subscription Edition when users access their mail via Outlook Web Access. Attackers can trigger the vulnerability by sending a specially crafted email that executes arbitrary JavaScript code within the victim's browser context. Source

Extracted Entities

Vulnerabilities (1)