Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Security Feature Bypass Vulnerability
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Microsoft Exchange Server Elevation of Privilege Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Microsoft Exchange Server Information Disclosure Vulnerability
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Hi All, I hope you find this article helpful. I have been away for a bit so I’m a little behind. Let me know what you think.
There’s often more to do after an advisory like this. The usual flow is that a mitigation goes in, Health Checker shows green, and the ticket gets closed. The challenge is that this doesn’t always mean the actual exposure has been eliminated. The persistence side of the issue tends to get much less attention than the fix, so it can be overlooked even when some risk remains.
The gap that's easy to miss
CVE-2026-42897 is an OWA XSS that drops a forwarding rule in the victim's mailbox with no further interaction. CISA added it to the KEV catalog the day after disclosure, suggesting exploitation was already running before most teams read the advisory.
EEMS blocks future exploitation. It does not remove rules created before it was applied. A password reset doesn't remove them either. They keep running until someone finds and deletes them.
Where this breaks down
The pre-mitigation window exists in every environment. Its length depends on when EEMS was actually applied locally, not when the advisory was published. Health Checker reporting "Applied" doesn't confirm the rewrite rule is active. IE and Edge in IE-Mode don't support the CSP component. Those users stay exposed regardless of Health Checker status. For Exchange 2016 and 2019, the permanent patch only comes through Period 2 ESU. Organisations that didn't enrol before April 2026 have no standard patch path. That's in the advisory update notes, not the headline.
The forensic piece
IIS logs from the pre-mitigation window are the only record of whether malicious emails were delivered. Easy to lose before anyone thinks to preserve them.
The retrospective mailbox forwarding rule audit is what teams may treat as optional follow-up rather than first action. The PowerShell isn't complicated. Reviewing results in a large environment is.
Full, referenced, article at https://cyops.com.au/cve-2026-42897-your-attacker-may-still-be-there
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Microsoft Exchange Server Spoofing Vulnerability
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Microsoft Exchange Server Spoofing Vulnerability
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Microsoft Exchange Server Elevation of Privilege Vulnerability
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.