Microsoft Exchange Zero Day Under Attack No Patch Available
Microsoft Exchange just got hit with a zero-day that attackers are already abusing to steal mailboxes. CVE-2026-42897 is a cross-site scripting flaw in Outlook Web Access. Unauthenticated attackers send a crafted email that runs arbitrary JavaScript in the victim's browser session when opened in OWA.
CVSS 8.1.
No patch exists yet. Microsoft is shipping temporary mitigations through the Exchange Emergency Mitigation Service. Affects on-prem Exchange Server 2016, 2019, and Subscription Edition. Exchange Online is not affected.
CISA added it to the KEV catalog on May 15, requiring federal agencies to remediate by May 29.
