Threat reportVulnerabilityTL-2026-0780

Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day CVE-2026-42897 Exploited In the Wild

criticalACTIVE

Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day (TL-2026-0780), also tracked as Exchange OWA XSS Zero-Day, is a critical-severity software vulnerability scored CVSS 8.1, first published 2026-06-11. It has no confirmed attribution, affects Microsoft Exchange Server 2016, references 1 CVE (CVE-2026-42897), maps to 17 MITRE ATT&CK techniques (T1056, T1059, T1087), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
8.1/10Critical
CVEs
1Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0780

Threat ID
TL-2026-0780
Also known as
Exchange OWA XSS Zero-Day, Exchange Server May 2026 OWA Spoofing Vulnerability
Severity
CRITICAL
CVSS
8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, healthcare, enterprise, education
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
16

Malware and tooling in Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day

Malware and tooling: Exchange On-Premises Mitigation Tool (EOMT.ps1)

How Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day works

CVE-2026-42897 is an actively exploited cross-site scripting (XSS) zero-day in Microsoft Exchange Server Outlook Web Access (OWA). An unauthenticated attacker emails a victim a weaponized message; when opened in OWA under certain interaction conditions, attacker-supplied JavaScript runs in the victim's authenticated browser session, enabling session-token theft, mailbox impersonation, and email spoofing. Microsoft assesses it as 'Exploitation Detected' and CISA added it to the KEV catalog.

CVE-2026-42897 is a cross-site scripting vulnerability (CWE-79, improper neutralization of user-supplied input during web page generation) in the Outlook Web Access (OWA) component of on-premises Microsoft Exchange Server. The flaw lets an unauthenticated, remote attacker craft an email whose HTML body carries an obfuscated JavaScript payload — delivered via inline event-handler attributes that survive OWA's sanitization path. No attacker authentication is required and the only victim interaction needed is opening the message in OWA. When the message is rendered, the script executes inside the victim's already-authenticated OWA browser context.

Because the code runs in the victim's authenticated session, the attacker never has to touch the Exchange server directly. Post-exploitation the script can harvest OWA session cookies and authentication/session tokens, impersonate the mailbox owner, read and exfiltrate mailbox contents, send email as the victim, and silently create inbox forwarding or transport rules. Captured session tokens can be replayed to pivot into other identity-linked Microsoft 365 services — SharePoint, Teams, and cloud storage — without triggering a fresh authentication challenge. Microsoft classifies the primary impact as spoofing over the network.

Microsoft published the advisory on 2026-05-14 with an 'Exploitation Detected' assessment (Microsoft CNA CVSS 3.1 base 8.1, vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N; NVD reassessed the impact at base 6.1, vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). CISA added CVE-2026-42897 to the Known Exploited Vulnerabilities catalog on 2026-05-15 with a Federal Civilian Executive Branch remediation deadline of 2026-05-29. For roughly four weeks there was no permanent patch; defenders depended on the Exchange Emergency Mitigation (EM/EEMS) Service, which auto-deploys the M2.1.x mitigation — a URL Rewrite rule applying a Content Security Policy 'script-src-attr none' directive to block inline event-handler execution — or the Exchange On-Premises Mitigation Tool (EOMT) for disconnected/air-gapped environments. The CSP-based mitigation does NOT protect clients using Internet Explorer or Microsoft Edge in Internet Explorer Mode, because IE does not support CSP, and it breaks several OWA features (calendar printing, inline image display in the reading pane, OWA Light, and published calendars). Permanent security updates shipped 2026-06-09 for Exchange Server SE RTM, 2019 CU14/CU15, and 2016 CU23. Microsoft also warned that EM and feature-flighting services stop accepting configurations from July 2026 unless servers are updated to the June 2026 build or later. Exchange Online (Microsoft 365) is not affected.

Attribution remains unconfirmed as of reporting; the tradecraft (a no-server-touch OWA XSS that blends into normal mailbox activity and bypasses attachment- and link-focused controls) reflects moderate-to-advanced capability. No public network IOCs (IPs, domains, hashes) have been released, which is consistent with the low-forensic-artifact nature of client-side XSS; detection therefore centers on behavioral signals in IIS/OWA logs, mailbox-rule auditing, and session-token abuse.

MITRE ATT&CK techniques used in TL-2026-0780

Credential Access

T1056 Input Capture; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Discovery

T1087 Account Discovery

Persistence

T1098 Account Manipulation

Collection

T1114 Email Collection

collection

T1185 Browser Session Hijacking

Initial Access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566 Phishing

Lateral Movement

T1534 Internal Spearphishing; T1550 Use Alternate Authentication Material

lateral-movement

T1550 Use Alternate Authentication Material

stealth

T1564 Hide Artifacts

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1608 Stage Capabilities

Affected products and versions in Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day

  • Microsoft — Exchange Server 2016
    Vulnerable versions: 2016 CU23 (all update levels)
    Fixed in: 2016 CU23 with June 2026 Security Update
  • Microsoft — Exchange Server 2019
    Vulnerable versions: 2019 CU14 (all update levels); 2019 CU15 (all update levels)
    Fixed in: 2019 CU14/CU15 with June 2026 Security Update
  • Microsoft — Exchange Server Subscription Edition (SE)
    Vulnerable versions: SE RTM
    Fixed in: SE RTM with June 2026 Security Update
  • Microsoft — Exchange Online (Microsoft 365)
    Fixed in: Not affected

Remediation for Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day

Patches

  • Exchange Server SE RTM June 2026 Security Update
  • Exchange Server 2019 CU14/CU15 June 2026 Security Update
  • Exchange Server 2016 CU23 June 2026 Security Update

Immediate actions

  • Ensure the Exchange Emergency Mitigation (EM/EEMS) Service is enabled so the automatic M2.1.x mitigation is applied to Exchange Server 2016, 2019, and SE
  • For disconnected/air-gapped environments, run the Exchange On-Premises Mitigation Tool (EOMT) to apply the URL Rewrite CSP mitigation manually
  • Restrict or block OWA access from Internet Explorer and Microsoft Edge Internet Explorer Mode, since the CSP mitigation does not protect those clients
  • Audit mailboxes for unauthorized inbox forwarding/transport rules and anomalous mail-send activity

Workarounds

  • Exchange Emergency Mitigation (EM/EEMS) automatic mitigation M2.1.x (CSP script-src-attr 'none' URL Rewrite rule)
  • Exchange On-Premises Mitigation Tool (EOMT) for offline application

Longer-term hardening

  • Apply the June 2026 Exchange security updates to reach a permanently patched build
  • Update servers to the June 2026 level or later before July 2026 to retain EM/feature-flighting configuration support
  • Migrate from out-of-support Exchange to Exchange Server Subscription Edition for ongoing security updates
  • Deploy session-token binding/conditional access and monitor for OWA session-token reuse from anomalous contexts

CVEs associated with Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day

CVE-2026-42897

Weaknesses (CWE) in Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day

CWE-79

Timeline of Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day

  • Active exploitation confirmed at disclosure; attackers send weaponized emails that execute JavaScript in victims' OWA sessions to steal session tokens and impersonate mailboxes.
  • Microsoft publishes the MSRC advisory for CVE-2026-42897, assessing it as 'Exploitation Detected' (active in-the-wild exploitation of the Exchange OWA XSS flaw). Microsoft CNA CVSS 3.1 base 8.1.
  • Microsoft publishes the automatic Exchange Emergency Mitigation (EM/EEMS) mitigation M2.1.x (URL Rewrite CSP 'script-src-attr none') for Exchange 2016, 2019, and SE; EOMT available for offline use.
  • CISA adds CVE-2026-42897 to the Known Exploited Vulnerabilities catalog, setting a Federal Civilian Executive Branch remediation deadline of 2026-05-29.
  • Public reporting highlights a five-day-old zero-day with no permanent patch and a growing list of mitigation side-effects (broken OWA print, inline images, OWA Light) plus IE/Edge IE-Mode coverage gaps.
  • CISA KEV remediation deadline for Federal Civilian Executive Branch agencies to apply mitigations for CVE-2026-42897.
  • Microsoft releases permanent June 2026 security updates for Exchange Server SE RTM, 2019 CU14/CU15, and 2016 CU23, providing the definitive fix.
  • Exchange Emergency Mitigation and feature-flighting services stop accepting configurations from July 2026 unless servers are updated to the June 2026 build or later.

Sources cited for Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day

Detection coverage for TL-2026-0780

As of 2026-06-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0780 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats