• News/
  • darkreading-20260518214351

Microsoft Exchange Zero-Day Under Attack, No Patch Available

Dark Reading
·
Rob Wright
·
Published May 18, 2026
·
Updated

Microsoft on Thursday disclosed a zero-day vulnerability in Exchange that's under active exploitation, but four days later customers are still awaiting a patch. The zero-day, tracked as CVE-2026-42897, affects Exchange Outlook Web Access (OWA) and enables an unauthorized attacker to execute spoofing attacks over a network. According to Microsoft, the zero-day stems from a cross-site scripting (XSS) flaw, which is one of the most common software vulnerabilities found by security researchers, frequently making the Open Web Application Security Project's (OWASP) Top 10 lists. "An attacker could exploit this issue by sending a specially crafted email to a user," Microsoft said in an advisory. "If the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context." CVE-2026-42897 was disclosed two days after a large Patch Tuesday release last week that, ironically, contained no zero-days. The Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploit Vulnerabilities (KEV) catalog on Friday. CVE-2026-42897 affects the on-premise versions of Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE). Microsoft assigned the zero-day a CVSS score of 8.1, though the NIST's National Vulnerability Database assigned it a medium-severity 6.1 score. Microsoft did not provide details about the potential scope of cyberattacks, but in an advisory p...

Read full article

Affected Software

3 affected components
Microsoft Exchange Server=2016
Microsoft Exchange Server=2019
Microsoft Exchange Server=Subscription Edition (SE)
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability in Microsoft Exchange that is currently being exploited, with no patch available yet.

2

What security implications are discussed?

The article highlights the risks associated with the active exploitation of the CVE-2026-42897 vulnerability in Microsoft Exchange.

3

What software products are affected by the vulnerability?

The vulnerability affects Microsoft Exchange Server 2016, 2019, and the Subscription Edition.

4

How long has the vulnerability been disclosed?

The vulnerability was disclosed four days prior to the publication of the article.

5

What can customers do while awaiting a patch?

The article does not specify mitigation measures, but customers should monitor for updates from Microsoft and enhance their security practices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203