Microsoft patches Exchange Server zero-day exploited in attacks
Microsoft has issued updates for an actively exploited Exchange Server flaw that can run JavaScript in Outlook Web Access. It affects Exchange 2016, 2019, and Subscription Edition.
Intelligence analysis by GPT-5.4 Mini

Microsoft says CVE-2026-42897 lets remote attackers send a crafted email that can trigger JavaScript execution in a user's browser when Outlook Web Access is opened under certain conditions. The company and CISA both treated it as actively exploited, with admins told to patch quickly and keep mitigations enabled.
Microsoft found a hole in Exchange mail servers that bad actors were already using. It was like a bad envelope that could hide a trick note, and when someone opened it in the web mail app, harmful code could run in the browser.
Analysis
What Microsoft fixed
Microsoft released June 2026 security updates for Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition to address CVE-2026-42897. The flaw is described as a high-severity spoofing issue that can be exploited remotely with no privileges.
How the attack works
According to Microsoft, an attacker can send a specially crafted email to a user. If that user opens the message in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript may run in the browser context. The article says this is a cross-site scripting issue aimed at OWA users.
What admins are being told to do
Microsoft advised customers to install the June 2026 Security Updates “as soon as possible” and to leave the temporary mitigation in place for added protection. The company said the mitigation provides an additional layer of defense while further improvements are released.
Wider context
CISA added the vulnerability to its catalog of flaws exploited in the wild on May 15 and told U.S. government agencies to patch within two weeks, by May 29. The article also notes that over the past five years, CISA has listed 20 Microsoft Exchange Server vulnerabilities as exploited, and ransomware gangs have used 14 of them.
Bottom line
The story is another reminder that Exchange remains a high-value target. The combination of active exploitation, browser-side code execution, and broad enterprise deployment makes timely patching and layered mitigation the central takeaway.
Key points
- Microsoft patched CVE-2026-42897, an actively exploited Exchange Server zero-day.
- The flaw can let remote attackers run JavaScript through Outlook Web Access under certain conditions.
- Affected products include Exchange Server 2016, 2019, and Subscription Edition.
- CISA added the flaw to its exploited-in-the-wild list and set a patch deadline for U.S. agencies.
- Microsoft says admins should install the June 2026 updates and keep mitigations enabled.
Microsoft has now shipped fixes for the affected Exchange versions, which gives administrators a clear path to reduce exposure. Keeping the temporary mitigation in place adds another layer of defense while more protections are rolled out.
If servers stay unpatched, attackers can keep using crafted emails to trigger browser-side code execution against OWA users. The article also suggests Exchange remains a repeat target, which raises the risk of follow-on exploitation across exposed deployments.



