IC Technology & Surveillance — 2026-05-18
CISA Adds Microsoft Exchange Server Zero-Day to Known Exploited Vulnerabilities Catalog
BLUFDespite an unpatched, no-click Exchange vector, a publicly disclosed breach of a US federal network is unlikely by 30 June 2026, as espionage-grade intrusions typically surface long after compromise.
CISA added CVE-2026-42897, an actively exploited Microsoft Exchange Server cross-site scripting vulnerability with a CVSS score of 8.1, to its Known Exploited Vulnerabilities catalog on May 16, setting a May 29 remediation deadline for federal civilian agencies under Binding Operational Directive 22-01. The flaw affects Outlook Web Access and can be triggered when a user opens a specially crafted email, executing malicious JavaScript in the user's session without further interaction. Microsoft confirmed active exploitation in the wild but disclosed no details about observed attacks; no permanent patch is available, with only temporary mitigations released. The vulnerability surfaced two days after Microsoft's May 2026 Patch Tuesday, which addressed 138 other vulnerabilities.
AnalysisA publicly disclosed breach of an FCEB network by 30 June 2026 is
unlikely, with no patch available and federal agencies racing a May 29 deadline. Low confidence reflects a single secondary source and no technical reporting on observed attacks. The OWA vector requires only that a user open a crafted email, granting attackers direct access to credentials and internal communications, but Exchange zero-days historically surface months after initial compromise rather than within the disclosure window. Private-sector on-premises Exchange deployments are the likelier exploitation targets, where victim organizations outnumber agencies and network visibility is lower. A confirmed government breach would trigger mandatory incident reporting, cross-agency emergency patching, and congressional notification beyond BOD 22-01.
2 sources
- U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog - Security Affairs
- CVE-2026-42897: Exchange Server Zero-Day Executes JavaScript Through Your Inbox - Hive Security
View in full brief →