IC Technology & Surveillance — 2026-05-17
CISA adds Microsoft Exchange cross-site scripting vulnerability to KEV catalog amid active exploitation
BLUFAbsent a patch, active exploitation of OWA-facing Exchange servers likely persists through mid-June 2026, leaving federal and critical infrastructure networks exposed even where EEMS mitigations are applied.
Analysis
With no patch release date announced and EEMS as the only available mitigation, Exchange servers in OWA-exposed environments face a sustained risk window extending well into June. Sourced solely from MSRC and amplified without independent collection by secondary outlets, the picture carries moderate confidence: active exploitationlikely persists through mid-June 2026, sustained by a low-interaction trigger and an unpatched attack surface across SE, 2016, and 2019 builds. Exploitation may reflect opportunistic scanning rather than targeted intrusion, in which case organizations with EEMS already enabled carry minimal residual risk. FCEB security officers must treat EEMS configuration as a durable operational posture, not a bridge to a patch release, and defer server changes that would disable the service.
With no patch release date announced and EEMS as the only available mitigation, Exchange servers in OWA-exposed environments face a sustained risk window extending well into June. Sourced solely from MSRC and amplified without independent collection by secondary outlets, the picture carries moderate confidence: active exploitation
4 sources
- CISA Adds One Known Exploited Vulnerability to Catalog
- Microsoft warns of Exchange zero-day flaw exploited in attacks -
BleepingComputer - On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email -
The Hacker News - Unpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897) -
Help Net Security