Exchange Server vulnerability exploited; Microsoft issues patches
Microsoft’s latest Patch Tuesday release addresses an actively exploited Exchange Server vulnerability, tracked as CVE-2026-42897.
The company first alerted Exchange users to ongoing zero-day attacks targeting this flaw on May 14, at which point it also provided temporary mitigation guidance—essentially a reminder that attackers rarely wait for a formal invitation.
A day later, on May 15, the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, directing federal agencies to remediate the issue by May 29.
CVE-2026-42897 is classified as a spoofing and cross-site scripting (XSS) vulnerability affecting Exchange Server Subscription Edition, as well as Exchange Server 2016 and 2019.
According to Microsoft, the flaw can be exploited through a specially crafted email. If a user opens the message in Outlook Web Access and specific interaction conditions are met, arbitrary JavaScript may execute within the browser—demonstrating once again that even a routine email can carry more than just an inbox notification.
Microsoft released official patches for the vulnerability on June 9 and strongly recommends that customers apply the updates without delay.