CVE-2026-42897Active Exploitation(microsoft / exchange_server)

CRITICALCVSS 6.1 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 86 mentions and remains active

Immediate actions

  • Patch microsoft exchange_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-29. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-79

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_server
  • exchange_server_subscription_edition

Threat summary

  • Active exploitation appears in 305 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 425 mentions across 62 observed days

What's happening

  • Active exploitation reported across 305 signals
  • Exploit tool or code specified in 16 signals
  • PoC mentioned or linked in 33 signals
  • Patch or workaround mentioned in 193 signals
  • Technical details provided in 226 signals
  • Disclosure: 46 classified signals
  • Peaked 60d ago at 86 mentions (2026-05-15); latest day: 1
  • 425 total mentions across 62 days

Affected systems

Vendors
Products
exchange_serverexchange_server_subscription_edition

2 versions affected across 2 products

Deep dive

Activity timeline425 mentions / 62d
022436586Mentions · 2026-05-14: 17Mentions · 2026-05-15: 86Mentions · 2026-05-16: 29Mentions · 2026-05-17: 16Mentions · 2026-05-18: 44Mentions · 2026-05-19: 24Mentions · 2026-05-20: 27Mentions · 2026-05-21: 6Mentions · 2026-05-22: 7Mentions · 2026-05-23: 3Mentions · 2026-05-24: 4Mentions · 2026-05-25: 6Mentions · 2026-05-26: 4Mentions · 2026-05-27: 1Mentions · 2026-05-28: 4Mentions · 2026-05-29: 6Mentions · 2026-05-30: 4Mentions · 2026-06-02: 1Mentions · 2026-06-03: 1Mentions · 2026-06-05: 2Mentions · 2026-06-08: 1Mentions · 2026-06-09: 5Mentions · 2026-06-10: 14Mentions · 2026-06-11: 17Mentions · 2026-06-12: 3Mentions · 2026-06-13: 1Mentions · 2026-06-14: 1Mentions · 2026-06-15: 6Mentions · 2026-06-16: 1Mentions · 2026-06-17: 1Mentions · 2026-06-23: 2Mentions · 2026-06-24: 2Mentions · 2026-06-30: 1Mentions · 2026-07-02: 1Mentions · 2026-07-03: 7Mentions · 2026-07-04: 2Mentions · 2026-07-06: 1Mentions · 2026-07-07: 1Mentions · 2026-07-09: 1Mentions · 2026-07-14: 1Mentions · 2026-07-15: 2Mentions · 2026-07-19: 1Mentions · 2026-07-20: 1Mentions · 2026-07-21: 1Mentions · 2026-07-28: 3Mentions · 2026-07-29: 6Mentions · 2026-07-30: 24Mentions · 2026-07-31: 8Mentions · 2026-08-01: 4Mentions · 2026-08-02: 1Mentions · 2026-08-03: 1Mentions · 2026-08-04: 2Mentions · 2026-08-05: 1Mentions · 2026-08-06: 1Mentions · 2026-08-07: 1Mentions · 2026-08-10: 1Mentions · 2026-08-13: 1Mentions · 2026-08-15: 1Mentions · 2026-08-28: 1Mentions · 2026-09-02: 1Mentions · 2026-09-09: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-05-15: 7PoC Mentioned / Linked · 2026-05-16: 1PoC Mentioned / Linked · 2026-05-17: 2PoC Mentioned / Linked · 2026-05-18: 3PoC Mentioned / Linked · 2026-05-19: 3PoC Mentioned / Linked · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-21: 1PoC Mentioned / Linked · 2026-05-22: 1PoC Mentioned / Linked · 2026-05-24: 1PoC Mentioned / Linked · 2026-05-25: 1PoC Mentioned / Linked · 2026-05-29: 1PoC Mentioned / Linked · 2026-06-10: 1PoC Mentioned / Linked · 2026-06-11: 1PoC Mentioned / Linked · 2026-07-02: 1PoC Mentioned / Linked · 2026-07-20: 1PoC Mentioned / Linked · 2026-07-29: 1PoC Mentioned / Linked · 2026-07-30: 5PoC Mentioned / Linked · 2026-07-31: 1Exploit Tool / Code · 2026-05-15: 1Exploit Tool / Code · 2026-05-17: 1Exploit Tool / Code · 2026-07-02: 1Exploit Tool / Code · 2026-07-20: 1Exploit Tool / Code · 2026-07-30: 5Exploit Tool / Code · 2026-07-31: 4Exploit Tool / Code · 2026-08-01: 1Exploit Tool / Code · 2026-08-04: 1Exploit Tool / Code · 2026-08-10: 1Active Exploitation · 2026-05-14: 5Active Exploitation · 2026-05-15: 72Active Exploitation · 2026-05-16: 22Active Exploitation · 2026-05-17: 7Active Exploitation · 2026-05-18: 38Active Exploitation · 2026-05-19: 19Active Exploitation · 2026-05-20: 20Active Exploitation · 2026-05-21: 5Active Exploitation · 2026-05-22: 5Active Exploitation · 2026-05-23: 1Active Exploitation · 2026-05-24: 2Active Exploitation · 2026-05-25: 5Active Exploitation · 2026-05-28: 3Active Exploitation · 2026-05-29: 5Active Exploitation · 2026-05-30: 1Active Exploitation · 2026-06-05: 1Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-06-09: 4Active Exploitation · 2026-06-10: 9Active Exploitation · 2026-06-11: 12Active Exploitation · 2026-06-12: 1Active Exploitation · 2026-06-13: 1Active Exploitation · 2026-06-15: 5Active Exploitation · 2026-06-16: 1Active Exploitation · 2026-06-23: 2Active Exploitation · 2026-06-24: 2Active Exploitation · 2026-06-30: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-07-03: 6Active Exploitation · 2026-07-04: 2Active Exploitation · 2026-07-06: 1Active Exploitation · 2026-07-07: 1Active Exploitation · 2026-07-19: 1Active Exploitation · 2026-07-20: 1Active Exploitation · 2026-07-28: 3Active Exploitation · 2026-07-29: 4Active Exploitation · 2026-07-30: 19Active Exploitation · 2026-07-31: 5Active Exploitation · 2026-08-01: 3Active Exploitation · 2026-08-04: 2Active Exploitation · 2026-08-05: 1Active Exploitation · 2026-08-07: 1Active Exploitation · 2026-08-10: 1Active Exploitation · 2026-08-13: 1Active Exploitation · 2026-08-28: 1Active Exploitation · 2026-09-15: 1Patch / Workaround · 2026-05-14: 8Patch / Workaround · 2026-05-15: 33Patch / Workaround · 2026-05-16: 13Patch / Workaround · 2026-05-17: 5Patch / Workaround · 2026-05-18: 17Patch / Workaround · 2026-05-19: 16Patch / Workaround · 2026-05-20: 12Patch / Workaround · 2026-05-21: 4Patch / Workaround · 2026-05-22: 4Patch / Workaround · 2026-05-23: 3Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-25: 3Patch / Workaround · 2026-05-26: 2Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-28: 3Patch / Workaround · 2026-05-29: 4Patch / Workaround · 2026-05-30: 3Patch / Workaround · 2026-06-05: 1Patch / Workaround · 2026-06-08: 1Patch / Workaround · 2026-06-09: 4Patch / Workaround · 2026-06-10: 6Patch / Workaround · 2026-06-11: 10Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-13: 1Patch / Workaround · 2026-06-14: 1Patch / Workaround · 2026-06-15: 6Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-23: 2Patch / Workaround · 2026-06-24: 2Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-03: 2Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-14: 1Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-07-21: 1Patch / Workaround · 2026-07-28: 2Patch / Workaround · 2026-07-29: 2Patch / Workaround · 2026-07-30: 7Patch / Workaround · 2026-07-31: 2Patch / Workaround · 2026-08-01: 1Patch / Workaround · 2026-08-15: 1Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-09-09: 1Technical Details · 2026-05-14: 8Technical Details · 2026-05-15: 49Technical Details · 2026-05-16: 19Technical Details · 2026-05-17: 8Technical Details · 2026-05-18: 22Technical Details · 2026-05-19: 14Technical Details · 2026-05-20: 16Technical Details · 2026-05-21: 3Technical Details · 2026-05-22: 5Technical Details · 2026-05-23: 3Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 5Technical Details · 2026-05-26: 3Technical Details · 2026-05-27: 1Technical Details · 2026-05-28: 2Technical Details · 2026-05-29: 2Technical Details · 2026-05-30: 2Technical Details · 2026-06-02: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-09: 3Technical Details · 2026-06-10: 10Technical Details · 2026-06-11: 6Technical Details · 2026-06-12: 2Technical Details · 2026-06-13: 1Technical Details · 2026-06-14: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-17: 1Technical Details · 2026-06-24: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-15: 1Technical Details · 2026-07-20: 1Technical Details · 2026-07-28: 1Technical Details · 2026-07-29: 3Technical Details · 2026-07-30: 11Technical Details · 2026-07-31: 8Technical Details · 2026-08-01: 3Technical Details · 2026-08-02: 1Technical Details · 2026-08-04: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-15: 105-1405-2005-2606-0306-1206-2307-0607-2008-0108-0709-0909-15
Signal classification8 categories
Active Exploitation
28065.9%
Patch
5813.6%
Disclosure
4610.8%
General
317.3%
PoC
40.9%
Exploit
40.9%
Referenced assets240 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-1417
Active Exploitation4Disclosure5General3Patch5
2026-05-1586
Active Exploitation69Disclosure8General1Patch7PoC1
2026-05-1629
Active Exploitation21Disclosure2Exploit1General3Patch2
2026-05-1716
Active Exploitation7Discl1Disclosure5Exploit1General2
2026-05-1844
Active Exploitation37Disclosure2General3Patch2
2026-05-1924
Active Exploitation19False Positive1General2Patch2
2026-05-2027
Active Exploitation20Disclosure4General2Patch1
2026-05-216
Active Exploitation5PoC1
2026-05-227
Active Exploitation5Disclosure2
2026-05-233
Active Exploitation1Disclosure1Patch1
2026-05-244
Active Exploitation2Disclosure1General1
2026-05-256
Active Exploitation4General1Patch1
2026-05-264
Disclosure2General1Patch1
2026-05-271
Patch1
2026-05-284
Active Exploitation3Patch1
2026-05-296
Active Exploitation5Patch1
2026-05-304
Active Exploitation1Disclosure2General1
2026-06-021
Disclosure1
2026-06-031
General1
2026-06-052
Active Exploitation1Patch1
2026-06-081
Active Exploitation1
2026-06-095
Active Exploitation2Patch3
2026-06-1014
Active Exploitation5Disclosure2General2Patch5
2026-06-1117
Active Exploitation8Disclosure1General2Patch6
2026-06-123
Active Exploitation1General2
2026-06-131
Patch1
2026-06-141
Patch1
2026-06-156
Patch6
2026-06-161
Disclosure1
2026-06-171
Patch1
2026-06-232
Active Exploitation2
2026-06-242
Active Exploitation1Patch1
2026-06-301
Active Exploitation1
2026-07-021
Active Exploitation1
2026-07-037
Active Exploitation6Patch1
2026-07-042
Active Exploitation2
2026-07-061
Active Exploitation1
2026-07-071
Active Exploitation1
2026-07-091
Patch1
2026-07-141
Patch1
2026-07-152
General1Patch1
2026-07-191
Active Exploitation1
2026-07-201
Active Exploitation1
2026-07-211
Patch1
2026-07-283
Active Exploitation3
2026-07-296
Active Exploitation4Exploit1Patch1
2026-07-3024
Active Exploitation18Disclosure1Exploit1General1Patch1PoC2
2026-07-318
Active Exploitation5Disclosure3
2026-08-014
Active Exploitation3Disclosure1
2026-08-021
Active Exploitation1
2026-08-031
Disclosure1
2026-08-042
Active Exploitation2
2026-08-051
Active Exploitation1
2026-08-061
General1
2026-08-071
Active Exploitation1
2026-08-101
Active Exploitation1
2026-08-131
Active Exploitation1
2026-08-151
Disclosure1
2026-08-281
Active Exploitation1
2026-09-021
General1
2026-09-091
Patch1
2026-09-151
Active Exploitation1
Full discourse20 posts
  • Fazt@FaztTech
    Active Exploitation

    Las últimas semanas en ciberseguridad están siendo brutales: → GitHub: 3,800 repos internos filtrados (20 mayo) → GitHub: CVE-2026-3854, RCE con un solo git push → npm: 42 paquetes de Tanstack envenenados (12M descargas/semana) → Microsoft: 138 vulnerabilidades parcheadas este mes → Exchange (Microsoft): CVE-2026-42897, JS arbitrario abriendo un correo Y Hoy le encuentran un 0 day a Nginx y están investigando una versión maliciosa de NxConsole Y lo más loco: el mismo grupo (TeamPCP) está detrás de los ataques a npm Y a GitHub. No son incidentes aislados, es una campaña coordinada contra la infraestructura que TODOS usamos. En 2025 se publicaron casi medio millón de paquetes maliciosos. Y seguimos instalando a ciegas. Y de momento no parece que vaya a terminar estos problemas

    Post summary

    The post highlights multiple recent CVEs, noting active exploitation by TeamPCP against GitHub and npm, while also mentioning that Microsoft has patched numerous vulnerabilities this month.

    24227141.4K32673.4K
    59.1K followersView on X
  • International Cyber Digest@IntCyberDigest
    Active Exploitation

    ‼️🚨 BREAKING: Microsoft Exchange Server CVE-2026-42897 lets an attacker execute arbitrary JavaScript in a victim's browser just by getting them to open an email in Outlook Web Access. It is being exploited in the wild. Microsoft classified it as... "spoofing." 🤔 Affected: on-premises Exchange Server 2016, 2019 and SE. Exchange Online is not impacted.

    Post summary

    Microsoft’s CVE‑2026‑42897 allows arbitrary JavaScript execution in Outlook Web Access and is already being exploited in the wild, targeting on‑prem Exchange 2016/2019 and SE, with no patch or mitigation described.

    161841796128992.5K
    193.5K followersView on X
  • Medusa@medusa_0xf
    Active Exploitation

    Microsoft just confirmed CVE-2026-42897 is being actively exploited in the wild. The target? Outlook Web Access. No malicious link. No attachment. Just open the email. I broke down exactly how the attack works 👇 https://openyoutu.be/KofP7cUedT4 https://t.co/B2xDlCyYHO

    Post summary

    The post confirms that Microsoft has identified active exploitation of CVE-2026-42897 against Outlook Web Access and points to a video explanation of the attack.

    964530921967.8K
    9.1K followersView on X
  • 三輪信雄@NobMiwa
    General

    CVE-2026-42897 の脆弱性、ただのメールで感染

    Post summary

    The snippet mentions CVE-2026-42897 and notes that infection can occur via email, but provides no further technical, exploit, or mitigation details.

    043221812743.4K
    8.4K followersView on X
  • Kostas@Kostastsale
    PoC

    Proofpoint published research on OWAReaper, a browser implant exploiting CVE-2026-42897 in Outlook Web Access. What stands out is that everything happens inside the browser. It uses GitHub queries for commands and CDN proxies or DNS tunnelling for exfil. For most orgs out there, this is impossible to detect... All it takes is a crafted email that triggers JS inside an authenticated OWA session in the browser. The XSS executes under the context of the victim’s session permissions. OWAReaper can: • Steal mailbox data • Persist through localStorage and IndexedDB • Use GitHub commit search for C2 • Exfiltrate through CDN proxies and DNS tunneling Patching blocks initial exploitation, but existing persistence may remain. If you're running on-prem Exchange, first of all, I'm sorry 😂; you should hunt for suspicious mailbox permissions, OAuth tokens, and browser storage artifacts. Also check for unusual GitHub, CDN, or DNS traffic that matches the pattern from this article (good luck with that). https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit

    Post summary

    The blog explains how OWAReaper abuses CVE‑2026‑42897 to execute XSS in Outlook Web Access, using GitHub queries and CDN/DNS tunnelling for exfiltration; patching stops initial exploitation but may not remove persistence.

    141217710719.0K
    20.7K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 On-prem Microsoft Exchange Server CVE-2026-42897 is under active exploitation. The CVSS 8.1 spoofing flaw stems from XSS and can allow arbitrary JavaScript execution when crafted emails are opened in Outlook Web Access under certain conditions. Read: https://thehackernews.com/2026/05/on-prem-microsoft-exchange-server-cve.html

    Post summary

    CVE‑2026‑42897 is actively exploited; it permits XSS-based JavaScript execution via crafted emails in Outlook Web Access, with no patch or mitigation mentioned.

    64111041838.5K
    1.9M followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    ماودي اخرب عليكم العيد 😆 لكن في ثغرة مستغلة حالياً في خوادم Microsoft Exchange (On-Prem) 📍 رقم الثغرة: CVE-2026-42897 | التقييم: 8.1 مايكروسوفت أدرجتها تحت حالة "Exploitation Detected"، يعني الثغرة يتم استغلالها فعلياً في هجمات حقيقية . ⚠️ تصنيفها الرسمي هو (Spoofing)، لكن اساسها عبارة عن ثغرة (XSS). المهاجم يرسل إيميل مكتوب بطريقه معينه، وإذا فتحه الضحية عبر (Outlook Web Access - OWA) وتحققت شروط معينة، يقدر المهاجم يشغّل كود JavaScript خبيث داخل المتصفح وبنفس صلاحيات وسياق جلسة الضحية في الـ OWA.

    Post summary

    Microsoft reports CVE‑2026‑42897 is actively exploited in real attacks, where attackers send crafted emails that trigger an XSS flaw in Exchange OWA, allowing malicious JavaScript to run with the victim’s session privileges. No PoC, exploit code, or patch details are provided.

    681786031.1K
    50.0K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    👇 One crafted email. Open it in OWA. Arbitrary JavaScript runs in your browser. That’s CVE-2026-42897 — actively exploited now. Hits *every* update level of on-prem Exchange 2016/2019/SE (Online safe). CISA added to KEV — feds must mitigate by May 29. Permanent patch coming. Apply mitigations NOW.

    Post summary

    CVE‑2026‑42897 is being actively exploited against all Exchange versions; users should apply the available mitigations and await the permanent patch.

    2230821921.9K
    1.9M followersView on X
  • The Hacker News@TheHackersNews
    Patch

    UPDATE: Microsoft has patched the actively exploited on-prem Exchange flaw (CVE-2026-42897). Patch now, and keep the existing mitigation on for extra protection. Affects Exchange Server 2016, 2019, and SE. Details 👇 https://thehackernews.com/2026/05/on-prem-microsoft-exchange-server-cve.html

    Post summary

    The text announces that Microsoft has released a patch for the actively exploited CVE-2026-42897 on Exchange Server, urging users to apply it immediately.

    329174109.8K
    2.0M followersView on X
  • cr3ghost@cr3ghost
    Active Exploitation

    Opening the email is the entire exploit chain. No attachment, no link, no click. TA488 is abusing CVE-2026-42897, an XSS in Outlook Web Access. The payload hides in the Base64 of the social media icons in the message body. The implant is pure JavaScript running in the OWA browser context. Zero host footprint, nothing on disk for EDR to catch. Then it does the part worth studying: enumerates Outlook add-ins with ReadWriteMailbox, steals OAuth tokens via GetClientAccessToken, and calls UpdateFolder to grant the 'Default' user Owner permissions on every mail folder. That grant is server-side. Re-image the endpoint. Rotate every credential. They still have the mailbox. Infrastructure predates Microsoft's out-of-band patch by two months, so 0day is plausible. If your Exchange hygiene does not include auditing folder ACLs granted to Default, that is a blind spot. Author: @proofpoint Link in description

    Post summary

    The text reports that threat actor TA488 is actively exploiting CVE‑2026‑42897 in Outlook Web Access, injecting JavaScript in email bodies to steal OAuth tokens and grant elevated mailbox permissions, indicating real‑world malicious activity.

    215063343.9K
    8.6K followersView on X
  • Sekurak@Sekurak
    Disclosure

    Uwaga na krytyczną podatność 0-day w Microsoft Exchange (CVE-2026-42897) ❌ Luka jest aktywnie ❌ wykorzystywana i dotyczy OWA (Outlook Web Access) ❌ Microsoft opisuje scenariusz ataku: ℹ️ Atakujący wysyła do ofiary odpowiednio spreparowanego maila ℹ️ Ofiara otwiera maila w przeglądarce webowej (tj. w OWA) ℹ️ Po wykonaniu pewnej akcji (np. najechaniu na jakiś element), po cichu wykonuje się kod JavaScript w przeglądarce ofiary [czyli mamy klasyczny persistent XSS] ❌ Atakujący w ten sposób może mieć np. dostęp do emaili ofiary (poprzez bezpośrednie pobranie maili czy przechwycenie ciastka sesyjnego). Najpewniej może też wysyłać e-maile ❌ podszywając się perfekcyjnie pod ofiarę. ✅ Microsoft wydał na razie tymczasowe zalecenia (workarounds) - patrz komentarz, pełne patche będą wkrótce. CVE-2026-42897. Podatne są: Microsoft Exchange Server 2016 / 2019 / SE

    Post summary

    Microsoft Exchange Server 2016/2019/SE is affected by a critical 0‑day CVE‑2026‑42897, a persistent XSS triggered in OWA via JavaScript, with temporary workarounds in place and full patches pending.

    290811310.1K
    43.9K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️We added Microsoft Exchange Server cross-site scripting vulnerability CVE-2026-42897 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/KmNyvDq9tg

    Post summary

    The post notes that Microsoft Exchange Server CVE‑2026‑42897, a cross‑site scripting flaw, has been added to the DHS Known Exploited Vulnerabilities Catalog, indicating it is actively being used in attacks, and directs readers to a link for further details.

    42905579.3K
    300.1K followersView on X
  • Microsoft Exchange@MSFTExchange
    Patch

    Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 | Microsoft Community Hub https://techcommunity.microsoft.com/blog/Exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498

    Post summary

    Microsoft has announced that it is addressing the CVE‑2026‑42897 vulnerability in Exchange Server, indicating forthcoming patch or mitigation steps.

    0161481314.6K
    69.2K followersView on X
  • blackorbird@blackorbird
    PoC

    TA488 Comes for Outlook with Another Half-Click Exploit CVE-2026-42897 (Outlook Web Access) -> OWAReaper Backdoor https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit https://t.co/pOyHpRSnNp

    Post summary

    The post references CVE-2026-42897 tied to a new Outlook Web Access exploit and suggests a PoC is available, but lacks details on active attacks, patches, or technical specifics.

    013145135.4K
    43.8K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Explotan vulnerabilidad CVE-2026-42897 en Microsoft Exchange Server local mediante correos manipulados Microsoft ha detectado una vulnerabilidad de spoofing y cross-site scripting (CVE-2026-42897) que afecta a versiones locales de Exchange https://blog.elhacker.net/2026/05/explotan-vulnerabilidad-cve-2026-42897.html

    Post summary

    The post reports active exploitation of CVE‑2026‑42897 against local Microsoft Exchange Server via manipulated emails, noting spoofing and cross‑site scripting issues but offering no PoC, patch, or extensive technical detail.

    111042143.5K
    141.0K followersView on X
  • CiberBaur@BotBauR
    Active Exploitation

    🚨 Acaba de confirmarse: la agencia de ciberseguridad de EE. UU., CISA, agregó una vulnerabilidad en Microsoft Exchange Server a su catálogo de vulnerabilidades explotadas conocidas, con un puntaje CVSS de 8.1. La vulnerabilidad, identificada como CVE-2026-42897, afecta a los productos Microsoft Exchange Server 2016, Exchange Server 2019 y Exchange Server Subscription Edition, y se relaciona con un problema de Cross-Site Scripting (XSS) en el componente Outlook Web Access (OWA). El ataque se puede llevar a cabo a través de un correo electrónico especialmente diseñado que, al ser abierto en OWA, puede ejecutar código JavaScript malicioso, lo que podría permitir a los atacantes acceder a información confidencial o tomar el control del sistema. Los sistemas afectados deben ser parcheados lo antes posible para evitar explotaciones. ¿Estás en riesgo? Revisa esto: actualiza tus servidores Exchange a la última versión y aplica los parches de seguridad correspondientes. https://securityaffairs.com/192240/hacking/u-s-cisa-adds-a-flaw-in-microsoft-exchange-server-to-its-known-exploited-vulnerabilities-catalog.html

    Post summary

    CISA confirms CVE‑2026‑42897 as actively exploited in Microsoft Exchange Server via XSS, urging immediate patching.

    05046133.0K
    460 followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day https://securityaffairs.com/192204/security/cve-2026-42897-microsoft-confirms-active-exploitation-of-exchange-server-zero-day.html

    Post summary

    Microsoft confirms that CVE-2026-42897 is being actively exploited against Exchange Server, but no PoC, exploit code, or patch details are provided in the text.

    08033103.0K
    158.6K followersView on X
  • ANSSI@ANSSI_FR
    Active Exploitation

    ⚠️ Vulnérabilité Microsoft Exchange Server. 📢 Le CERT-FR a publié une alerte de sécurité concernant la vulnérabilité activement exploitée CVE-2026-42897, affectant Microsoft Exchange Server. Plus d'informations sur : ➡️ https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-005/ https://t.co/O99qmbbMwU

    Post summary

    CERT‑FR has issued a security alert for CVE‑2026‑42897, a Microsoft Exchange Server vulnerability that is actively being exploited, with further information available through the provided link.

    22001975.2K
    84.0K followersView on X
  • Virus Bulletin@virusbtn
    Active Exploitation

    Proofpoint analyses a campaign from Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploiting Outlook CVE-2026-42897 & targeting US & European government entities, as well as telecommunications, financial, hospitality & aerospace sectors. https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit https://t.co/l14SE8woxu

    Post summary

    Proofpoint reports that the Russia‑aligned TA488 threat actor is actively exploiting the Outlook CVE-2026-42897 vulnerability against US and European government entities and critical infrastructure sectors.

    06026122.2K
    61.6K followersView on X
  • The Dustin Childs@dustin_childs
    Patch

    Wow - #Microsoft releases an emergency patch for an Exchange spoofing bug in the wild. Looks like it's confined to OWA and Preview Pane is NOT a vector. Still, start your test and deployment engines! https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897

    Post summary

    Microsoft has issued an emergency patch for the CVE-2026-42897 Exchange spoofing bug that is actively exploited in the wild, primarily affecting Outlook Web Access; the update is available via the Microsoft Security Response Center.

    011019104.8K
    2.4K followersView on X
CPE platform detail40 entries

40 of 40 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server_subscription_edition---

Explore more