Skip to content
Microsoft Patches Critical Exchange Server Zero-Day Vulnerability CVE-2026-42897

Microsoft Patches Critical Exchange Server Zero-Day Vulnerability CVE-2026-42897

First seen 11 Jun 2026, 08:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 12, 2026 at 08:38 UTC
  • CVE-2026-42897 allows remote execution of JavaScript via Outlook Web Access.
  • Microsoft released security updates on June 10, 2026, urging immediate deployment.
  • CISA ordered U.S. agencies to patch affected Exchange servers by May 29, 2026.

Microsoft has patched a high-severity zero-day vulnerability in Exchange Server, tracked as CVE-2026-42897, which allows attackers to execute arbitrary JavaScript via crafted emails in Outlook Web Access. The flaw affects Exchange Server 2016, 2019, and Subscription Edition, enabling remote exploitation without user privileges. Microsoft disclosed the vulnerability on May 14, 2026, and it was added to CISA's list of actively exploited vulnerabilities the following day. Security updates were released on June 10, 2026, with strong recommendations for immediate deployment. The Cybersecurity and Infrastructure Security Agency has ordered U.S. government agencies to patch their systems by May 29, 2026. This vulnerability is part of a troubling trend, as CISA has previously added 20 Microsoft Exchange vulnerabilities to its exploited list in the last five years.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-05-14
CVE-2026-42897 published
Microsoft disclosed a spoofing vulnerability in Exchange Server allowing JavaScript execution via emails.
Cybersecuritynews
2026-05-15
CVE-2026-42897 added to CISA KEV
CISA confirmed active exploitation of the vulnerability and added it to its list of exploited flaws.
Bleepingcomputer
2026-05-29
CISA patch deadline for U.S. agencies
CISA mandated that U.S. government agencies patch their Exchange servers to mitigate the vulnerability.
Bleepingcomputer
2026-06-10
Microsoft releases security updates
Microsoft issued patches for Exchange Server to address CVE-2026-42897, advising immediate application.
Bleepingcomputer

More articles in this cluster (27)

Following this threat?

Track Microsoft and CVE-2020-0688 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed