CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day — No Patch, Active Exploitation
How threat actors are actively weaponizing an unpatched stored XSS zero-day in Microsoft Exchange OWA to hijack mailbox session tokens.
CVE-2026-42897
Severity: CVSS 8.8
Status: ⚠️ Unpatched Active Zero-Day Exploitation
Target Component: Microsoft Exchange Server OWA
Disclosed on May 14, CVE-2026-42897 is a stored cross-site scripting (XSS) vulnerability in Microsoft Exchange Server's Outlook Web Access (OWA) that Microsoft has confirmed is being actively exploited in the wild — with no permanent patch available as of May 19, 2026.
Vulnerability Overview
CVE-2026-42897 is classified as an improper neutralization of input during web page generation (CWE-79) — a stored XSS in the OWA component of on-premises Exchange Server. The CVSS v3.1 base score is 8.1 (High).
- Affected versions: Exchange Server 2016 (all CU levels), Exchange Server 2019 (all CU levels), Exchange Server Subscription Edition
- Not affected: Exchange Online (Microsoft 365)
- Authentication required: None (attacker only needs an email address for the target)
- User interaction: Required — victim must open the email in OWA
Attack Chain
- Craft the payload: The attacker constructs a message body containing unsanitized JavaScript that bypasses OWA's content filter via encoding tricks.
- Deliver via email: The attacker sends the crafted email to any OWA user. No phishing click is required beyond opening the email in the OWA web interface.
- JavaScript executes in authenticated session: When the recipient opens the message in OWA, the injected JavaScript runs inside their authenticated browser session with full access to the mailbox context.
- Session hijacking and post-exploitation: Observed post-exploitation includes session token exfiltration, silent inbox rule creation forwarding to attacker-controlled addresses, mailbox content search, and mailbox impersonation.
Because the JavaScript executes in the victim's browser with their existing authentication, the attacker never interacts with the Exchange server directly — making server-side detection extremely difficult.
Active Exploitation
Microsoft confirmed on May 14 that CVE-2026-42897 is being exploited in the wild. As of May 19, no permanent patch is available. Organizations with on-premises Exchange and OWA exposed to the internet are at highest risk. There is no CISA KEV listing as of this writing — though that may change rapidly.
What to Do
Apply Microsoft's temporary mitigation immediately via the Exchange Team Blog (published May 14).
Audit inbox rules across all mailboxes:
Get-Mailbox -ResultSize Unlimited | Get-InboxRule | Where-Object {$_.ForwardTo -ne $null -or $_.RedirectTo -ne $null} | Select-Object MailboxOwnerID, Name, ForwardTo, RedirectTo | Export-Csv -Path C:\inbox_rules_audit.csvRestrict OWA exposure: If OWA doesn't need to be internet-facing, restrict access to trusted IP ranges via WAF or network ACLs.
Enable Enhanced Logging: Ensure IIS logs capture full request details for OWA endpoints to reconstruct email-open events for forensics.
Monitor for a patch: Subscribe to the Exchange Team Blog and MSRC for CVE-2026-42897 update notifications.
→ Back to the Week of May 21 Security Roundup