Junglewise Threat Intelligence

CVE-2026-42897: Microsoft Exchange Server cross-site scripting in Outlook Web Access

CVE-2026-42897 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2026-05-14

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server, the widely used corporate email and calendaring platform, is vulnerable to a security flaw in its Outlook Web Access (OWA) component. An attacker can use this vulnerability to run malicious scripts in a user's web browser if the user interacts with a specially crafted link or page. This could allow an attacker to steal sensitive session information, impersonate users, or gain unauthorized access to corporate email accounts.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Microsoft Exchange Server due to improper neutralization of input during web page generation within Outlook Web Access (OWA). The vulnerability is classified as CWE-79 and allows an unauthenticated, remote attacker to execute arbitrary JavaScript in the context of a victim's browser. Exploitation requires a network-based attack vector and user interaction, such as clicking a malicious link. Successful exploitation can lead to session hijacking, unauthorized data access, and spoofing. This vulnerability has been reported as exploited in the wild.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2026-05-14: disclosed
  • 2026-05-15: advisory: NVD publication date
  • 2026-05-15: exploited: Reported as exploited in the wild in advisory metadata.

Related threats