IC Technology & Surveillance — 2026-05-17

CISA adds Microsoft Exchange cross-site scripting vulnerability to KEV catalog amid active exploitation

BLUFAbsent a patch, active exploitation of OWA-facing Exchange servers likely persists through mid-June 2026, leaving federal and critical infrastructure networks exposed even where EEMS mitigations are applied.

CVE-2026-42897, a CVSS 8.1 cross-site scripting and spoofing flaw in Microsoft Exchange Server (Subscription Edition, 2016, and 2019), was disclosed by Microsoft on May 14, 2026 and added to CISA's Known Exploited Vulnerabilities catalog the following day. The vulnerability resides in Outlook Web Access and is triggered when a victim opens a crafted email under certain interaction conditions, allowing arbitrary JavaScript execution in the browser. No patch exists yet; Microsoft's recommended interim mitigation uses the Exchange Emergency Mitigation Service, which applies the workaround automatically when enabled. Federal Civilian Executive Branch agencies face a May 29, 2026 remediation deadline.

Analysis
With no patch release date announced and EEMS as the only available mitigation, Exchange servers in OWA-exposed environments face a sustained risk window extending well into June. Sourced solely from MSRC and amplified without independent collection by secondary outlets, the picture carries moderate confidence: active exploitation likely persists through mid-June 2026, sustained by a low-interaction trigger and an unpatched attack surface across SE, 2016, and 2019 builds. Exploitation may reflect opportunistic scanning rather than targeted intrusion, in which case organizations with EEMS already enabled carry minimal residual risk. FCEB security officers must treat EEMS configuration as a durable operational posture, not a bridge to a patch release, and defer server changes that would disable the service.
4 sources
  1. CISA Adds One Known Exploited Vulnerability to Catalog
  2. Microsoft warns of Exchange zero-day flaw exploited in attacks - BleepingComputer
  3. On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email - The Hacker News
  4. Unpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897) - Help Net Security

View in full brief →

UNCLASSIFIED // OPEN SOURCE