Microsoft has disclosed a new critical security vulnerability affecting on-premise versions of Exchange Server that is already being exploited by attackers. The vulnerability, CVE -2026-42897 , has a CVSS score of 8.1 and poses a serious threat to thousands of businesses worldwide.

This is a spoofing bug resulting from a cross-site scripting (XSS). An anonymous researcher has been credited with discovering and reporting the issue to Microsoft.
According to the announcement , "improper input neutralization during web page creation in Microsoft Exchange Server allows an unauthorized attacker to perform network spoofing."
This type of vulnerability is particularly dangerous as it affects the trust level of webmail, where users rely on visual cues to determine the authenticity of messages and senders.
See also: Microsoft Exchange Server: Vulnerabilities exploited to distribute keylogger
Microsoft has already identified attacks that exploit the vulnerability. Attackers can exploit the flaw by sending a maliciously crafted email to the user, which when opened in Outlook Web Access (OWA) and under certain interaction conditions, could allow arbitrary JavaScript code to be executed in the web browser environment . Active exploitation of the vulnerability means that threat actors have already developed functional exploits and are using them in real attacks, which significantly increases the risk and the urgent need for immediate protection measures.
Exchange Server: Affected versions and protection measures
According to Microsoft, Exchange Online is not affected by this vulnerability, which limits the scope to on-premises installations. The following on-premises versions of Exchange Server are vulnerable:
- Exchange Server 2016 (any update level),
- Exchange Server 2019 (any update level) and
- Exchange Server Subscription Edition (SE) (any update level).
This means that almost all modern on-premise Exchange are potentially vulnerable, regardless of the level of installed security updates.
Microsoft is providing a temporary workaround through the Exchange Emergency Mitigation while we prepare a permanent fix for the bug. The service automatically provides mitigation through URL rewrite configuration and is enabled by default. If it is not enabled, users are advised to enable it.
This approach allows Microsoft to provide rapid protection without requiring immediate patch installation, which is critical when there is an active exploit.

For organizations that cannot use the Exchange Emergency Mitigation Service due to air-gap or other operational limitations, Microsoft has outlined a series of actions. First, they should download the latest version of the Exchange on-premises Mitigation Tool (EOMT) from aka.ms/UnifiedEOMT. Then, apply the mitigation to each server individually or to all servers at once by running the script through an elevated Exchange Management Shell (EMS):
- Single server: .\EOMT.ps1 -CVE “CVE-2026-42897”
- All servers: Get-ExchangeServer | Where-Object { $_.ServerRole -ne “Edge” } | .\EOMT.ps1 -CVE “CVE-2026-42897”
This alternative method is especially important for organizations with strict security policies that do not allow automatic updates or external connections.
See also: Azerbaijani energy company suffered repeated Microsoft Exchange exploit
Microsoft reported a known issue where the mitigation displays “Mitigation invalid for this exchange version” in the Description field. The Exchange team clarified that “this issue is “cosmetic” and the mitigation is APPLIED successfully if the status displays as 'Applied'”. The company is investigating how to address this issue. This clarification is critical for administrators who may misinterpret the error message and believe that the mitigation was not applied correctly.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Protection strategies and best practices
In addition to immediately implementing Microsoft mitigations , organizations should adopt a holistic security approach to protect against such threats. This includes enabling multi-factor authentication (MFA) for all email accounts, enforcing strict Content Security Policies (CSP) on web applications, and using advanced anti-phishing tools that can detect and block malicious emails before they reach users. In addition, regularly educating users about social engineering techniques and the signs of malicious emails is essential to creating a strong first line of defense.

There are currently no details on how the vulnerability is being exploited, the identity of the threat actor behind the activity, or the scale of such efforts. It is also unclear who the targets are and whether any of these attacks were successful. The lack of public details about the attacks may indicate either that the attacks are in their early stages, or that Microsoft and security researchers are trying to limit the dissemination of information that could help other attackers develop their own exploits.
See also: Microsoft re-releases Exchange Server security update
Organizations running on-premise Exchange should take immediate protective measures and remain vigilant for any signs of a breach.
According to The Hacker News, the vulnerability highlights the ongoing threat businesses face from on-premise email installations. CVE-2026-42897 is yet another example of why organizations must maintain a proactive security posture and be ready to respond quickly to new threats.
