Microsoft on Thursday disclosed a zero-day vulnerability in Exchange that's under active exploitation, but four days later customers are still awaiting a patch. The zero-day, tracked as CVE-2026-42897, affects Exchange Outlook Web Access (OWA) and enables an unauthorized attacker to execute spoofing attacks over a network. According to Microsoft, the zero-day stems from a cross-site scripting (XSS) flaw, which is one of the most common software vulnerabilities found by security researchers, frequently making the Open Web Application Security Project's (OWASP) Top 10 lists. "An attacker could exploit this issue by sending a specially crafted email to a user," Microsoft said in an advisory. "If the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context." CVE-2026-42897 was disclosed two days after a large Patch Tuesday release last week that, ironically, contained no zero-days. The Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploit Vulnerabilities (KEV) catalog on Friday. CVE-2026-42897 affects the on-premise versions of Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE). Microsoft assigned the zero-day a CVSS score of 8.1, though the NIST's National Vulnerability Database assigned it a medium-severity 6.1 score. Microsoft did not provide details about the potential scope of cyberattacks, but in an advisory p...
Microsoft Exchange Zero-Day Under Attack, No Patch Available
Dark Reading
·Rob Wright
·Published May 18, 2026
·Updated
Affected Software
3 affected components
Microsoft Exchange Server=2016
Microsoft Exchange Server=2019
Microsoft Exchange Server=Subscription Edition (SE)
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day vulnerability in Microsoft Exchange that is currently being exploited, with no patch available yet.
2
What security implications are discussed?
The article highlights the risks associated with the active exploitation of the CVE-2026-42897 vulnerability in Microsoft Exchange.
3
What software products are affected by the vulnerability?
The vulnerability affects Microsoft Exchange Server 2016, 2019, and the Subscription Edition.
4
How long has the vulnerability been disclosed?
The vulnerability was disclosed four days prior to the publication of the article.
5
What can customers do while awaiting a patch?
The article does not specify mitigation measures, but customers should monitor for updates from Microsoft and enhance their security practices.