Top Advisory

Microsoft Exchange Server Vulnerability [Actively Exploited]

Severity Level: High

Date: 10/06/2026

Ref: CERT-NCSOC-0240

Components Affected

Note: Exchange Online (Microsoft 365 hosted email) is not affected by this vulnerability.

Overview

A high-severity and actively exploited vulnerability (CVE-2026-42897) has been identified in on-premises Microsoft Exchange Server. By sending a specially crafted email, a remote attacker could cause arbitrary JavaScript to run in a victim’s browser session when the message is opened or previewed in Outlook Web Access (OWA). This can lead to email spoofing, session token theft, mailbox impersonation, and even the manipulation of mailbox rules.

Description

Multiple vulnerabilities have been discovered in Exchange Server, the most severe of which could allow for cross-site scripting (XSS) and spoofing. The attacker does not require any access to the server – a specifically crafted email delivered through the normal email pipeline, combined with certain user interactions, can execute JavaScript inside the browser session. This gives the attacker a route to steal session tokens, impersonate the mailbox owner, and even abuse mailbox rules.

Impact

Solution / Workarounds

Before applying changes, please visit the vendor's website for full details. Apply the vendor mitigations immediately and install the security update for affected Exchange Server versions as it becomes available through the June 2026 update cycle.

Recommended actions:

Vendor resources:

Reference

Disclaimer

The information provided herein is on an "as is" basis, without warranty of any kind.

Footer Advisory