CVE-2026-42897
Microsoft Exchange Server Spoofing Vulnerability
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
In plain language
AI Act nowCVE-2026-42897 is a cross-site scripting bug in Microsoft Exchange Server (OWA) that can let attackers trick users’ browsers into showing attacker-controlled content when they open a specially prepared email; if you run affected Exchange Server versions, you should treat this as actively exploited and act now.
CVE-2026-42897 is an actively exploited cross-site scripting (XSS) vulnerability in Microsoft Exchange Server’s Outlook Web Access (OWA) that enables attackers to inject and run arbitrary JavaScript in a victim’s browser by using a specially crafted email, leading to spoofed content and persistence via the OWAReaper backdoor.
What to do now
- Check whether you run Microsoft Exchange Server 2016 CU23, Microsoft Exchange Server 2019 CU14, Microsoft Exchange Server 2019 CU15, or Microsoft Exchange Server Subscription Edition RTM (often shown as “exchange server subscription edition”).
- Verify that your email users access mail through Outlook Web Access (OWA) in a way that opens emails in a web browser.
- Upgrade Exchange to the fixed versions: Exchange 2016 CU23 → 15.01.2507.069; Exchange 2019 CU14 → 15.02.1544.041; Exchange 2019 CU15 → 15.02.1748.046; Exchange Subscription Edition RTM → 15.02.2562.043.
- If you cannot patch immediately, follow Microsoft’s compensating/workaround steps from the update guide for CVE-2026-42897 now.
- After updating, review browser/email-related activity and Exchange logs for signs of OWA-based JavaScript execution and suspicious mailbox access, and continue monitoring for persistence attempts.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacksen·The Hacker News·
- 3rd August – Threat Intelligence Reporten-us·Check Point Research·
- Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC releaseden-us·Help Net Security·
- Max-severity Exchange server flaw under active exploitation by Kremlin hackersen·Ars Technica (Security)· Exploited Outlook Web Access (OWA) TA488
- Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)en-us·Help Net Security· Exploited Outlook Web Access (OWA) TA488
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotationen·The Hacker News· Exploited Microsoft Outlook Web Access Laundry Bear
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox accessen-us·BleepingComputer· Exploited Microsoft Exchange Outlook Web Access (OWA) Laundry Bear
- Microsoft исправила более 200 уязвимостей и шесть 0-day в своих продуктахru-ru·Хакер (xakep.ru)· Exploited Exchange Server rce
- Microsoft Patches Exploited Exchange Server Vulnerabilityen-us·SecurityWeek· Exploited Exchange Server web-app
- Microsoft patches Exchange Server zero-day exploited in attacksen-us·BleepingComputer· Exploited Exchange Server 2016 web-app
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-42897 and every CVE in our database. Create a free account — no credit card required.
Create Free Account