Microsoft Exchange Zero-Day Under Attack, No Patch Available
Want more insights like this?
Microsoft disclosed a zero-day in Exchange (CVE-2026-42897) on Thursday, May 14, and five days later customers are still waiting for a patch. CISA added it to the Known Exploited Vulnerabilities catalog the next day, giving federal agencies until June 5 to act.
The flaw sits in Outlook Web Access on on-premises Exchange — Exchange Online isn't affected — and allows spoofing over a network via cross-site scripting. Attackers send a specially crafted email that runs arbitrary JavaScript when it's opened in OWA. It affects Exchange Server 2016, 2019 and Subscription Edition. Microsoft scored it 8.1; NVD rates the same flaw 6.1, medium severity.
Security experts warn successful attacks could compromise mailboxes, steal session tokens, and enable business email compromise or ransomware. Microsoft's two temporary mitigations are the Exchange Emergency Mitigation Service, which it recommends and which has been on by default since 2021, and the updated Exchange On-Premises Mitigation Tool — expect OWA Print Calendar and OWA Light to break.
Updated August 13, 2026: Microsoft patched this on June 9 — Exchange SE build 15.2.2562.43 (KB5094139), 2019 CU15 15.2.1748.46, 2019 CU14 15.2.1544.41, and 2016 CU23 15.1.2507.69. The 2016 and 2019 updates are only available to organizations enrolled in Extended Security Updates, and Microsoft says to leave the mitigation in place after installing.
Source: Dark Reading