CISA adding CVE-2026-42897 to the Known Exploited Vulnerabilities catalog should be treated as an immediate priority signal for every organization running on-premises Microsoft Exchange. The vulnerability affects Exchange Outlook Web Access and is described as a cross-site scripting issue that can be triggered through a specially crafted email opened in OWA under certain conditions. CISA lists it as a Microsoft Exchange Server Cross-Site Scripting Vulnerability with a required action date of May 29, 2026.
Organizations should not dismiss this as “just XSS.” In the context of Exchange, browser-executed script can support spoofing, session abuse, user deception, and access to sensitive mail workflows. Until a permanent fix is available, administrators should follow Microsoft’s mitigation guidance, enable Exchange Emergency Mitigation Service where applicable, reduce OWA exposure, and monitor for suspicious activity. Exchange has been a favorite attacker target for years, because apparently one of the most sensitive systems in the enterprise also had to be one of the most repeatedly hunted.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria .
Source: CISA Adds One Known Exploited Vulnerability to Catalog via CISA Advisories — published 15 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.