CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day — No Patch, Active Exploitation

How threat actors are actively weaponizing an unpatched stored XSS zero-day in Microsoft Exchange OWA to hijack mailbox session tokens.

CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day — No Patch, Active Exploitation
📌
Security Roundup Series: Week of May 21, 2026 • 4 min read deep dive
🚨
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-42897 Severity: CVSS 8.8 Status: ⚠️ Unpatched Active Zero-Day Exploitation Target Component: Microsoft Exchange Server OWA

Disclosed on May 14, CVE-2026-42897 is a stored cross-site scripting (XSS) vulnerability in Microsoft Exchange Server's Outlook Web Access (OWA) that Microsoft has confirmed is being actively exploited in the wild — with no permanent patch available as of May 19, 2026.


Vulnerability Overview

CVE-2026-42897 is classified as an improper neutralization of input during web page generation (CWE-79) — a stored XSS in the OWA component of on-premises Exchange Server. The CVSS v3.1 base score is 8.1 (High).

  • Affected versions: Exchange Server 2016 (all CU levels), Exchange Server 2019 (all CU levels), Exchange Server Subscription Edition
  • Not affected: Exchange Online (Microsoft 365)
  • Authentication required: None (attacker only needs an email address for the target)
  • User interaction: Required — victim must open the email in OWA

Attack Chain

  1. Craft the payload: The attacker constructs a message body containing unsanitized JavaScript that bypasses OWA's content filter via encoding tricks.
  2. Deliver via email: The attacker sends the crafted email to any OWA user. No phishing click is required beyond opening the email in the OWA web interface.
  3. JavaScript executes in authenticated session: When the recipient opens the message in OWA, the injected JavaScript runs inside their authenticated browser session with full access to the mailbox context.
  4. Session hijacking and post-exploitation: Observed post-exploitation includes session token exfiltration, silent inbox rule creation forwarding to attacker-controlled addresses, mailbox content search, and mailbox impersonation.

Because the JavaScript executes in the victim's browser with their existing authentication, the attacker never interacts with the Exchange server directly — making server-side detection extremely difficult.


Active Exploitation

Microsoft confirmed on May 14 that CVE-2026-42897 is being exploited in the wild. As of May 19, no permanent patch is available. Organizations with on-premises Exchange and OWA exposed to the internet are at highest risk. There is no CISA KEV listing as of this writing — though that may change rapidly.


What to Do

Apply Microsoft's temporary mitigation immediately via the Exchange Team Blog (published May 14).

Audit inbox rules across all mailboxes:

Get-Mailbox -ResultSize Unlimited | Get-InboxRule | Where-Object {$_.ForwardTo -ne $null -or $_.RedirectTo -ne $null} | Select-Object MailboxOwnerID, Name, ForwardTo, RedirectTo | Export-Csv -Path C:\inbox_rules_audit.csv

Restrict OWA exposure: If OWA doesn't need to be internet-facing, restrict access to trusted IP ranges via WAF or network ACLs.

Enable Enhanced Logging: Ensure IIS logs capture full request details for OWA endpoints to reconstruct email-open events for forensics.

Monitor for a patch: Subscribe to the Exchange Team Blog and MSRC for CVE-2026-42897 update notifications.

→ Back to the Week of May 21 Security Roundup


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther