PT-2026-40978 · Microsoft · Exchange Server

CVE-2026-42897

·

Published

2026-05-14

·

Updated

2026-09-09

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition
Description An improper neutralization of input during web page generation in Outlook Web Access (OWA) allows an unauthorized remote attacker to perform cross-site scripting (XSS). By sending a specially crafted email, an attacker can execute arbitrary JavaScript within the victim's authenticated browser session when the email is opened. This can lead to session hijacking, credential theft, email spoofing, and unauthorized actions performed on behalf of the user. The issue has been actively exploited in the wild, including campaigns by threat actor TA488 (Void Blizzard) targeting government, finance, and telecommunications sectors. In some instances, this was used to deploy the OWAReaper malware, which maintains persistence within the OWA interface and exfiltrates data via HTTPS and DNS.
Recommendations For Microsoft Exchange Server 2016, update to CU23 (requires enrollment in the Period 2 Extended Security Update program). For Microsoft Exchange Server 2019, update to CU14 or CU15 (requires enrollment in the Period 2 Extended Security Update program). For Microsoft Exchange Server Subscription Edition, apply the RTM update. Enable the Exchange Emergency Mitigation Service (EEMS) to automatically apply temporary protections. For air-gapped environments, run the Exchange On-Premises Mitigation Tool (EOMT) using the command .EOMT.ps1 -CVE "CVE-2026-42897". Restrict external exposure of the Outlook Web Access interface where possible. Avoid using the OWA web interface and use updated desktop clients until permanent patches are applied.

Exploit

Fix

RCE

DoS

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06919
CVE-2026-42897

Affected Products

Exchange Server