Skip to content
Active Exploitation of CVE-2026-42897 in Microsoft Exchange Server

Active Exploitation of CVE-2026-42897 in Microsoft Exchange Server

First seen 15 May 2026, 10:43 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •May 16, 2026 at 09:23 UTC
  • •CVE-2026-42897 is a critical vulnerability in Microsoft Exchange Server with active exploitation.
  • •Attackers can execute arbitrary JavaScript in victims' browsers via crafted emails in OWA.
  • •Immediate mitigations include enabling the Exchange Emergency Mitigation Service or using EOMT.

Microsoft has disclosed a critical vulnerability, CVE-2026-42897, affecting on-premises Exchange Server versions 2016, 2019, and Subscription Edition. This zero-day flaw allows attackers to execute arbitrary JavaScript via specially crafted emails opened in Outlook Web Access (OWA), with a CVSS score of 8.1. Active exploitation of this vulnerability has been confirmed, prompting Microsoft to recommend immediate mitigation measures. The Exchange Emergency Mitigation Service (EEMS) is available for automatic protection, while the Exchange On-premises Mitigation Tool (EOMT) can be used in air-gapped environments. No patches are currently available, and the vulnerability does not affect Exchange Online. Organizations are advised to enable EEMS or apply EOMT to reduce exposure until a permanent fix is released. Microsoft plans to provide updates for affected Exchange versions, but only for customers enrolled in the Extended Security Update (ESU) program.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 146d ago How this analysis works

Timeline

2026-05-14
CVE-2026-42897 published
Microsoft disclosed a critical spoofing vulnerability in Exchange Server affecting versions 2016, 2019, and SE.
Securityaffairs.Co
2026-05-15
Active exploitation confirmed
Microsoft confirmed that CVE-2026-42897 is being actively exploited in the wild, prompting urgent mitigation recommendations.
Bleepingcomputer
2026-05-15
Mitigation measures recommended
Microsoft advised administrators to enable the Exchange Emergency Mitigation Service or use the EOMT for temporary protection against the vulnerability.
Petri

More articles in this cluster (39)

Following this threat?

Track Microsoft and CVE-2026-42897 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed