Skip to main content Skip to search Skip to main navigation
Menu
BREAKING BREAKING Cybersecurity Score: 9/10

Microsoft Exchange Zero-Day: Critical Vulnerability Actively Exploited

Microsoft warns of an actively exploited zero-day vulnerability in Exchange Server. Attackers can inject JavaScript code via manipulated emails. Emergency patches available.

Critical zero-day vulnerability discovered in Microsoft Exchange Server

Microsoft has reported a serious security vulnerability in Exchange Server that is already being actively exploited by attackers. Classified as CVE-2026-42897, the vulnerability enables cross-site scripting attacks and is rated "critical" by Microsoft despite a CVSS score of 8.1. Particularly problematic: at the time of the warning, no regular software updates were yet available.

The vulnerability stems from insufficient input filtering when generating web pages and allows unauthenticated attackers on the network to carry out spoofing attacks. All versions of Exchange Server 2016, 2019 and Exchange Server Subscription Edition are affected across all update levels.

Attack scenario via Outlook Web Access

The vulnerability specifically targets Outlook Web Access (OWA). Attackers can send manipulated emails to potential victims. If users open these emails in OWA and certain interaction conditions are met, arbitrary JavaScript is executed in the victim's browser.

This attack scenario makes the vulnerability especially dangerous for businesses, since many organisations use OWA to give staff external email access. The fact that the flaw is already being exploited in the wild significantly increases the risk to affected systems.

Affected systems and versions

All Exchange Server installations of the following versions are affected by the vulnerability:

  • Exchange Server 2016 (all update levels)
  • Exchange Server 2019 (all update levels)
  • Exchange Server Subscription Edition (all update levels)

Emergency measures and available mitigations

Although no regular software updates are available yet, Microsoft is providing automatic mitigations via the Exchange Emergency Mitigation (EM) Service. This service has been distributed since September 2021 and is enabled by default. On systems where the EM service is active, Microsoft has already applied the protective measures automatically.

In addition, Microsoft is making a manual version of the mitigations available that administrators can implement themselves. These temporary fixes are intended to contain the vulnerability until permanent updates are available.

Known side effects of the protective measures

The mitigations that have been implemented come with a number of functional limitations that administrators should be aware of:

  • Printing calendars in OWA may no longer work
  • Inline images are no longer displayed correctly in the reading pane
  • OWA Light may no longer function properly (this feature is already considered deprecated)
  • The mitigation details may indicate that the mitigation is invalid for the Exchange version - however, this is merely a cosmetic issue

What matters is the "Applied" status in the mitigation details, which indicates that the protective measures were implemented successfully.

Significance for IT security

This vulnerability once again underlines the critical importance of email systems as a target for cybercriminals. Cross-site scripting attacks via email platforms can have far-reaching consequences, as they allow attackers to execute malicious code in the context of trusted applications.

For companies that rely on Exchange Server, this incident demonstrates the importance of proactive security measures. The fact that Microsoft is initially providing only emergency patches illustrates the complexity of modern IT infrastructures and the challenges involved in remediating critical vulnerabilities quickly.

Recommendations for IT administrators

Those responsible for IT should take the following steps immediately:

  • Verify that the Exchange Emergency Mitigation Service is enabled and working properly
  • Where necessary, manually implement the mitigations provided by Microsoft
  • Monitor Exchange systems for unusual activity
  • Raise user awareness of suspicious emails, particularly when accessed via OWA
  • Prepare to install permanent updates as soon as they become available

Outlook and permanent solution

Microsoft's Exchange team is already working on a permanent fix for the vulnerability. This proper solution is due to be released as an update for various Exchange versions: Exchange SE RTM, Exchange 2016 CU23 as well as Exchange Server 2019 CU14 and CU15.

Administrators running Exchange 2016 or 2019 should note, however, that they must be subscribed to the second stage of Extended Security Updates (ESU) to receive these updates. This underlines the importance of current maintenance contracts for critical infrastructure components.

The incident is a textbook example of how quickly the threat landscape in IT security can change. Zero-day vulnerabilities that are already being actively exploited demand fast and decisive responses from those responsible for IT. Microsoft's provision of automatic emergency measures demonstrates new approaches to handling critical security flaws.