PT-2026-40978 · Microsoft · Exchange Server
CVE-2026-42897
·
Published
2026-05-14
·
Updated
2026-09-09
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Exchange Server 2016
Microsoft Exchange Server 2019
Microsoft Exchange Server Subscription Edition
Description
An improper neutralization of input during web page generation in Outlook Web Access (OWA) allows an unauthorized remote attacker to perform cross-site scripting (XSS). By sending a specially crafted email, an attacker can execute arbitrary JavaScript within the victim's authenticated browser session when the email is opened. This can lead to session hijacking, credential theft, email spoofing, and unauthorized actions performed on behalf of the user. The issue has been actively exploited in the wild, including campaigns by threat actor TA488 (Void Blizzard) targeting government, finance, and telecommunications sectors. In some instances, this was used to deploy the OWAReaper malware, which maintains persistence within the OWA interface and exfiltrates data via HTTPS and DNS.
Recommendations
For Microsoft Exchange Server 2016, update to CU23 (requires enrollment in the Period 2 Extended Security Update program).
For Microsoft Exchange Server 2019, update to CU14 or CU15 (requires enrollment in the Period 2 Extended Security Update program).
For Microsoft Exchange Server Subscription Edition, apply the RTM update.
Enable the Exchange Emergency Mitigation Service (EEMS) to automatically apply temporary protections.
For air-gapped environments, run the Exchange On-Premises Mitigation Tool (EOMT) using the command
.EOMT.ps1 -CVE "CVE-2026-42897".
Restrict external exposure of the Outlook Web Access interface where possible.
Avoid using the OWA web interface and use updated desktop clients until permanent patches are applied.Exploit
Fix
RCE
DoS
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exchange Server