LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-42897: Microsoft Exchange Server Cross-Site Scripting Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 15, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 29, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-42897 to its Known Exploited Vulnerabilities catalog on May 15, 2026, with a federal patch deadline of May 29, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be…

Microsoft Exchange Server contains a cross-site scripting vulnerability in Outlook Web Access. Under certain interaction conditions during web page generation, an attacker can cause arbitrary JavaScript to execute in the browser context of a logged-in user. This matters because Exchange often handles sensitive corporate email and authentication tokens; successful exploitation can expose session data or allow actions on behalf of the victim without further credentials.

How it works

The weakness is classified as CWE-79, improper neutralization of input during web page generation. In Outlook Web Access, untrusted data reaches the page output without sufficient encoding or filtering. When the documented interaction conditions are present, the browser interprets attacker-controlled content as executable script rather than static text.

Am I affected? How to find it in your systems

Microsoft Exchange Server deployments that expose Outlook Web Access are the primary surface. Inventory on-premises Exchange servers and any configurations that allow external or internal access to OWA. Confirm exact versions and build numbers against the vendor advisory, as not all releases are affected. Review web server logs for anomalous requests that contain script tags or unusual parameters in OWA endpoints; correlate with authentication events that originate from unexpected user agents or IP addresses.

How to remediate

If you can't patch immediately

If your data may have been exposed

Actively exploited vulnerabilities of this class have led to account compromise and data access in past incidents. Run a free exposure scan of your organization's email domains against known breach data to identify any already-leaked credentials that could compound risk.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Microsoft
WeaknessCWE-79
Added to CISA KEVMay 15, 2026
Federal patch deadlineMay 29, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities