IC Technology & Surveillance — 2026-05-18

CISA Adds Microsoft Exchange Server Zero-Day to Known Exploited Vulnerabilities Catalog

BLUFDespite an unpatched, no-click Exchange vector, a publicly disclosed breach of a US federal network is unlikely by 30 June 2026, as espionage-grade intrusions typically surface long after compromise.

CISA added CVE-2026-42897, an actively exploited Microsoft Exchange Server cross-site scripting vulnerability with a CVSS score of 8.1, to its Known Exploited Vulnerabilities catalog on May 16, setting a May 29 remediation deadline for federal civilian agencies under Binding Operational Directive 22-01. The flaw affects Outlook Web Access and can be triggered when a user opens a specially crafted email, executing malicious JavaScript in the user's session without further interaction. Microsoft confirmed active exploitation in the wild but disclosed no details about observed attacks; no permanent patch is available, with only temporary mitigations released. The vulnerability surfaced two days after Microsoft's May 2026 Patch Tuesday, which addressed 138 other vulnerabilities.

Analysis
A publicly disclosed breach of an FCEB network by 30 June 2026 is unlikely, with no patch available and federal agencies racing a May 29 deadline. Low confidence reflects a single secondary source and no technical reporting on observed attacks. The OWA vector requires only that a user open a crafted email, granting attackers direct access to credentials and internal communications, but Exchange zero-days historically surface months after initial compromise rather than within the disclosure window. Private-sector on-premises Exchange deployments are the likelier exploitation targets, where victim organizations outnumber agencies and network visibility is lower. A confirmed government breach would trigger mandatory incident reporting, cross-agency emergency patching, and congressional notification beyond BOD 22-01.
2 sources
  1. U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog - Security Affairs
  2. CVE-2026-42897: Exchange Server Zero-Day Executes JavaScript Through Your Inbox - Hive Security

View in full brief →

UNCLASSIFIED // OPEN SOURCE