# Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day CVE-2026-42897 Exploited In the Wild

> CVE-2026-42897 is an actively exploited cross-site scripting (XSS) zero-day in Microsoft Exchange Server Outlook Web Access (OWA). An unauthenticated attacker emails a victim a weaponized message; when opened in OWA under certain interaction conditions, attacker-supplied JavaScript runs in the victim's authenticated browser session, enabling session-token theft, mailbox impersonation, and email spoofing. Microsoft assesses it as 'Exploitation Detected' and CISA added it to the KEV catalog.

- **Published:** 2026-06-11T00:00:00Z
- **Last reviewed:** 2026-06-11T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0780
- **ID:** TL-2026-0780
- **Severity:** CRITICAL (CVSS 8.1)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-42897

## Description

CVE-2026-42897 is a cross-site scripting vulnerability (CWE-79, improper neutralization of user-supplied input during web page generation) in the Outlook Web Access (OWA) component of on-premises Microsoft Exchange Server. The flaw lets an unauthenticated, remote attacker craft an email whose HTML body carries an obfuscated JavaScript payload — delivered via inline event-handler attributes that survive OWA's sanitization path. No attacker authentication is required and the only victim interaction needed is opening the message in OWA. When the message is rendered, the script executes inside the victim's already-authenticated OWA browser context.

Because the code runs in the victim's authenticated session, the attacker never has to touch the Exchange server directly. Post-exploitation the script can harvest OWA session cookies and authentication/session tokens, impersonate the mailbox owner, read and exfiltrate mailbox contents, send email as the victim, and silently create inbox forwarding or transport rules. Captured session tokens can be replayed to pivot into other identity-linked Microsoft 365 services — SharePoint, Teams, and cloud storage — without triggering a fresh authentication challenge. Microsoft classifies the primary impact as spoofing over the network.

Microsoft published the advisory on 2026-05-14 with an 'Exploitation Detected' assessment (Microsoft CNA CVSS 3.1 base 8.1, vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N; NVD reassessed the impact at base 6.1, vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). CISA added CVE-2026-42897 to the Known Exploited Vulnerabilities catalog on 2026-05-15 with a Federal Civilian Executive Branch remediation deadline of 2026-05-29. For roughly four weeks there was no permanent patch; defenders depended on the Exchange Emergency Mitigation (EM/EEMS) Service, which auto-deploys the M2.1.x mitigation — a URL Rewrite rule applying a Content Security Policy 'script-src-attr none' directive to block inline event-handler execution — or the Exchange On-Premises Mitigation Tool (EOMT) for disconnected/air-gapped environments. The CSP-based mitigation does NOT protect clients using Internet Explorer or Microsoft Edge in Internet Explorer Mode, because IE does not support CSP, and it breaks several OWA features (calendar printing, inline image display in the reading pane, OWA Light, and published calendars). Permanent security updates shipped 2026-06-09 for Exchange Server SE RTM, 2019 CU14/CU15, and 2016 CU23. Microsoft also warned that EM and feature-flighting services stop accepting configurations from July 2026 unless servers are updated to the June 2026 build or later. Exchange Online (Microsoft 365) is not affected.

Attribution remains unconfirmed as of reporting; the tradecraft (a no-server-touch OWA XSS that blends into normal mailbox activity and bypasses attachment- and link-focused controls) reflects moderate-to-advanced capability. No public network IOCs (IPs, domains, hashes) have been released, which is consistent with the low-forensic-artifact nature of client-side XSS; detection therefore centers on behavioral signals in IIS/OWA logs, mailbox-rule auditing, and session-token abuse.

## MITRE ATT&CK

- T1608 Stage Capabilities
- T1566 Phishing
- T1190 Exploit Public-Facing Application
- T1189 Drive-by Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1098 Account Manipulation
- T1564 Hide Artifacts
- T1550 Use Alternate Authentication Material
- T1539 Steal Web Session Cookie
- T1528 Steal Application Access Token
- T1056 Input Capture
- T1185 Browser Session Hijacking
- T1087 Account Discovery
- T1114 Email Collection
- T1550 Use Alternate Authentication Material
- T1534 Internal Spearphishing
- T1567 Exfiltration Over Web Service

## Sources

- [MSRC Security Update Guide — CVE-2026-42897](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897)
- [CISA Known Exploited Vulnerabilities Catalog — CVE-2026-42897](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42897)
- [NVD — CVE-2026-42897](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-42897)
- [Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 (Microsoft Exchange Team Blog)](https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498)
- [Microsoft Exchange Server 0-Day Exploited](https://cybersecuritynews.com/microsoft-exchange-server-0-day-exploited/)
- [Microsoft warns of Exchange zero-day flaw exploited in attacks (BleepingComputer)](https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-exchange-zero-day-flaw-exploited-in-attacks/)
- [CVE-2026-42897 Zero-Day Analysis: Exchange OWA XSS Exploited in the Wild (Rescana)](https://www.rescana.com/post/cve-2026-42897-zero-day-analysis-microsoft-exchange-server-owa-xss-vulnerability-exploited-in-the-wild/)
- [Deep Dive: CVE-2026-42897 — Spoofing Vulnerability in Microsoft Exchange OWA (Senthorus)](https://blog.senthorus.ch/posts/cve_2026_42897/)
- [CVE-2026-42897, the Exchange OWA XSS Zero-Day (Penligent)](https://www.penligent.ai/hackinglabs/cve-2026-42897/)
- [Exchange Server OWA Zero-Day CVE-2026-42897 Exploited With No Permanent Patch and New Mitigation Gaps (TechTimes)](https://www.techtimes.com/articles/316860/20260519/exchange-server-owa-zero-day-cve-2026-42897-exploited-no-permanent-patch-new-mitigation-gaps.htm)
- [Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers (Infosecurity Magazine)](https://www.infosecurity-magazine.com/news/microsoft-zeroday-exchange-servers/)
- [June 2026 Exchange Security Updates: ESU Gate, CVE-2026-42897, and OWA Mitigations (Windows Forum)](https://windowsforum.com/threads/june-2026-exchange-security-updates-esu-gate-cve-2026-42897-and-owa-mitigations.424133/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0780
