Threat reportVulnerabilityTL-2026-0780
Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day CVE-2026-42897 Exploited In the Wild
Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day (TL-2026-0780), also tracked as Exchange OWA XSS Zero-Day, is a critical-severity software vulnerability scored CVSS 8.1, first published 2026-06-11. It has no confirmed attribution, affects Microsoft Exchange Server 2016, references 1 CVE (CVE-2026-42897), maps to 17 MITRE ATT&CK techniques (T1056, T1059, T1087), and is covered by 9 detection rules and 16 indicators of compromise.
- CVSS
- 8.1/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-0780
- Threat ID
- TL-2026-0780
- Also known as
- Exchange OWA XSS Zero-Day, Exchange Server May 2026 OWA Spoofing Vulnerability
- Severity
- CRITICAL
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, healthcare, enterprise, education
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day
Malware and tooling: Exchange On-Premises Mitigation Tool (EOMT.ps1)
How Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day works
CVE-2026-42897 is an actively exploited cross-site scripting (XSS) zero-day in Microsoft Exchange Server Outlook Web Access (OWA). An unauthenticated attacker emails a victim a weaponized message; when opened in OWA under certain interaction conditions, attacker-supplied JavaScript runs in the victim's authenticated browser session, enabling session-token theft, mailbox impersonation, and email spoofing. Microsoft assesses it as 'Exploitation Detected' and CISA added it to the KEV catalog.
CVE-2026-42897 is a cross-site scripting vulnerability (CWE-79, improper neutralization of user-supplied input during web page generation) in the Outlook Web Access (OWA) component of on-premises Microsoft Exchange Server. The flaw lets an unauthenticated, remote attacker craft an email whose HTML body carries an obfuscated JavaScript payload — delivered via inline event-handler attributes that survive OWA's sanitization path. No attacker authentication is required and the only victim interaction needed is opening the message in OWA. When the message is rendered, the script executes inside the victim's already-authenticated OWA browser context.
Because the code runs in the victim's authenticated session, the attacker never has to touch the Exchange server directly. Post-exploitation the script can harvest OWA session cookies and authentication/session tokens, impersonate the mailbox owner, read and exfiltrate mailbox contents, send email as the victim, and silently create inbox forwarding or transport rules. Captured session tokens can be replayed to pivot into other identity-linked Microsoft 365 services — SharePoint, Teams, and cloud storage — without triggering a fresh authentication challenge. Microsoft classifies the primary impact as spoofing over the network.
Microsoft published the advisory on 2026-05-14 with an 'Exploitation Detected' assessment (Microsoft CNA CVSS 3.1 base 8.1, vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N; NVD reassessed the impact at base 6.1, vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). CISA added CVE-2026-42897 to the Known Exploited Vulnerabilities catalog on 2026-05-15 with a Federal Civilian Executive Branch remediation deadline of 2026-05-29. For roughly four weeks there was no permanent patch; defenders depended on the Exchange Emergency Mitigation (EM/EEMS) Service, which auto-deploys the M2.1.x mitigation — a URL Rewrite rule applying a Content Security Policy 'script-src-attr none' directive to block inline event-handler execution — or the Exchange On-Premises Mitigation Tool (EOMT) for disconnected/air-gapped environments. The CSP-based mitigation does NOT protect clients using Internet Explorer or Microsoft Edge in Internet Explorer Mode, because IE does not support CSP, and it breaks several OWA features (calendar printing, inline image display in the reading pane, OWA Light, and published calendars). Permanent security updates shipped 2026-06-09 for Exchange Server SE RTM, 2019 CU14/CU15, and 2016 CU23. Microsoft also warned that EM and feature-flighting services stop accepting configurations from July 2026 unless servers are updated to the June 2026 build or later. Exchange Online (Microsoft 365) is not affected.
Attribution remains unconfirmed as of reporting; the tradecraft (a no-server-touch OWA XSS that blends into normal mailbox activity and bypasses attachment- and link-focused controls) reflects moderate-to-advanced capability. No public network IOCs (IPs, domains, hashes) have been released, which is consistent with the low-forensic-artifact nature of client-side XSS; detection therefore centers on behavioral signals in IIS/OWA logs, mailbox-rule auditing, and session-token abuse.
MITRE ATT&CK techniques used in TL-2026-0780
Credential Access
T1056 Input Capture; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Discovery
Persistence
Collection
collection
T1185 Browser Session Hijacking
Initial Access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566 Phishing
Lateral Movement
T1534 Internal Spearphishing; T1550 Use Alternate Authentication Material
lateral-movement
T1550 Use Alternate Authentication Material
stealth
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Affected products and versions in Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day
- Microsoft — Exchange Server 2016
Vulnerable versions: 2016 CU23 (all update levels)
Fixed in: 2016 CU23 with June 2026 Security Update - Microsoft — Exchange Server 2019
Vulnerable versions: 2019 CU14 (all update levels); 2019 CU15 (all update levels)
Fixed in: 2019 CU14/CU15 with June 2026 Security Update - Microsoft — Exchange Server Subscription Edition (SE)
Vulnerable versions: SE RTM
Fixed in: SE RTM with June 2026 Security Update - Microsoft — Exchange Online (Microsoft 365)
Fixed in: Not affected
Remediation for Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day
Patches
- Exchange Server SE RTM June 2026 Security Update
- Exchange Server 2019 CU14/CU15 June 2026 Security Update
- Exchange Server 2016 CU23 June 2026 Security Update
Immediate actions
- Ensure the Exchange Emergency Mitigation (EM/EEMS) Service is enabled so the automatic M2.1.x mitigation is applied to Exchange Server 2016, 2019, and SE
- For disconnected/air-gapped environments, run the Exchange On-Premises Mitigation Tool (EOMT) to apply the URL Rewrite CSP mitigation manually
- Restrict or block OWA access from Internet Explorer and Microsoft Edge Internet Explorer Mode, since the CSP mitigation does not protect those clients
- Audit mailboxes for unauthorized inbox forwarding/transport rules and anomalous mail-send activity
Workarounds
- Exchange Emergency Mitigation (EM/EEMS) automatic mitigation M2.1.x (CSP script-src-attr 'none' URL Rewrite rule)
- Exchange On-Premises Mitigation Tool (EOMT) for offline application
Longer-term hardening
- Apply the June 2026 Exchange security updates to reach a permanently patched build
- Update servers to the June 2026 level or later before July 2026 to retain EM/feature-flighting configuration support
- Migrate from out-of-support Exchange to Exchange Server Subscription Edition for ongoing security updates
- Deploy session-token binding/conditional access and monitor for OWA session-token reuse from anomalous contexts
CVEs associated with Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day
Weaknesses (CWE) in Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day
Timeline of Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day
- Active exploitation confirmed at disclosure; attackers send weaponized emails that execute JavaScript in victims' OWA sessions to steal session tokens and impersonate mailboxes.
- Microsoft publishes the MSRC advisory for CVE-2026-42897, assessing it as 'Exploitation Detected' (active in-the-wild exploitation of the Exchange OWA XSS flaw). Microsoft CNA CVSS 3.1 base 8.1.
- Microsoft publishes the automatic Exchange Emergency Mitigation (EM/EEMS) mitigation M2.1.x (URL Rewrite CSP 'script-src-attr none') for Exchange 2016, 2019, and SE; EOMT available for offline use.
- CISA adds CVE-2026-42897 to the Known Exploited Vulnerabilities catalog, setting a Federal Civilian Executive Branch remediation deadline of 2026-05-29.
- Public reporting highlights a five-day-old zero-day with no permanent patch and a growing list of mitigation side-effects (broken OWA print, inline images, OWA Light) plus IE/Edge IE-Mode coverage gaps.
- CISA KEV remediation deadline for Federal Civilian Executive Branch agencies to apply mitigations for CVE-2026-42897.
- Microsoft releases permanent June 2026 security updates for Exchange Server SE RTM, 2019 CU14/CU15, and 2016 CU23, providing the definitive fix.
- Exchange Emergency Mitigation and feature-flighting services stop accepting configurations from July 2026 unless servers are updated to the June 2026 build or later.
Sources cited for Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day
- MSRC Security Update Guide — CVE-2026-42897
- CISA Known Exploited Vulnerabilities Catalog — CVE-2026-42897
- NVD — CVE-2026-42897
- Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 (Microsoft Exchange Team Blog)
- Microsoft Exchange Server 0-Day Exploited
- Microsoft warns of Exchange zero-day flaw exploited in attacks (BleepingComputer)
- CVE-2026-42897 Zero-Day Analysis: Exchange OWA XSS Exploited in the Wild (Rescana)
- Deep Dive: CVE-2026-42897 — Spoofing Vulnerability in Microsoft Exchange OWA (Senthorus)
- CVE-2026-42897, the Exchange OWA XSS Zero-Day (Penligent)
- Exchange Server OWA Zero-Day CVE-2026-42897 Exploited With No Permanent Patch and New Mitigation Gaps (TechTimes)
- Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers (Infosecurity Magazine)
- June 2026 Exchange Security Updates: ESU Gate, CVE-2026-42897, and OWA Mitigations (Windows Forum)
Detection coverage for TL-2026-0780
As of 2026-06-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0780 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.