CVE-2026-42897 (CVSS 8.1): Microsoft Exchange OWA Zero-Day Actively Exploited — No Patch Available
Microsoft confirmed active in-the-wild exploitation of a post-Patch-Tuesday Exchange Server OWA flaw with no permanent fix yet. CISA added it to the Known Exploited Vulnerabilities catalog with a May 29 deadline.
Microsoft Exchange Server is under active attack. CVE-2026-42897 — a CVSS 8.1 cross-site scripting and spoofing flaw in Outlook Web Access — is being exploited in the wild, and as of May 17, no permanent patch exists.
What the vulnerability allows
An attacker sends a specially crafted email to a victim. When that email is opened in OWA, arbitrary JavaScript executes inside the victim’s browser session. From there, an attacker can steal session tokens, redirect authentication flows, or pivot to further exploitation depending on the victim’s privilege level. No authentication is required from the attacker’s side — just delivery of the malicious message.
Who is affected
- Exchange Server 2016 (all current update rollups)
- Exchange Server 2019 (all current update rollups)
- Exchange Server Subscription Edition
Exchange Online (Microsoft 365) is not affected. This is exclusively an on-premises risk — which matters because a large portion of enterprise and government infrastructure still runs on-prem Exchange.
Current status and mitigation
Microsoft disclosed the vulnerability on May 14, days after the regular Patch Tuesday cycle. No out-of-band patch has followed. Instead, Microsoft’s Exchange Emergency Mitigation (EM) Service automatically pushed a configuration-level mitigation to servers where it is enabled.
Known side effects of the applied mitigation:
- OWA Print Calendar function is broken
- Inline images may fail to render
- OWA Light mode is non-functional
These are annoying, not catastrophic. But if your organization disabled EM Service — which some do for change-management reasons — the mitigation was not applied.
CISA added CVE-2026-42897 to the Known Exploited Vulnerabilities catalog on May 15. Federal Civilian Executive Branch (FCEB) agencies must remediate by May 29, 2026.
What to do right now
- Verify the Exchange Emergency Mitigation Service is running on all Exchange servers (
Get-ExchangeDiagnosticInfoand checkMitigationsApplied). - If EM Service is disabled, enable it or manually apply the mitigation Microsoft published in the security advisory.
- Monitor for unusual OWA session activity or JavaScript injection indicators in web application firewall logs.
- Watch for Microsoft’s out-of-band patch — it will arrive as a separate Cumulative Update or Security Update and should be applied immediately.
The absence of a patch this many days after disclosure is unusual for Microsoft and suggests the fix is non-trivial. Do not wait for Patch Tuesday.
Related reading
- Cybersecurity CISA Adds 8 Actively Exploited Flaws to KEV, Including Three Cisco SD-WAN Zero-Days
- Cybersecurity Adobe Patches Actively Exploited Acrobat Reader Zero-Day CVE-2026-34621 — CISA Orders Federal Patch by April 27
- Cybersecurity Fortinet Ships Emergency Patch for Actively Exploited FortiClient EMS Zero-Day CVE-2026-35616 (CVSS 9.1)