The active exploitation of CVE-2026-42897 in on-premises Microsoft Exchange Server is a serious reminder that email platforms remain one of the most targeted enterprise assets. Microsoft describes the issue as a spoofing vulnerability caused by cross-site scripting, where a crafted email opened in Outlook Web Access under certain interaction conditions could execute arbitrary JavaScript in the user’s browser context. That makes this especially concerning for organizations still running Exchange Server 2016, 2019, or Subscription Edition on-premises.

Organizations should immediately verify exposure, ensure the Exchange Emergency Mitigation Service is enabled, apply Microsoft’s recommended mitigation, and monitor for suspicious OWA activity. Exchange Online is not impacted, but on-premises environments should not wait for a permanent patch before acting. Email servers are already a favorite attacker playground; leaving an actively exploited Exchange flaw unmitigated is basically putting a welcome mat under the phishing mailbox.


Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue. "

Source: On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email via The Hacker News — published 15 May 2026.