Microsoft patches Exchange Server zero-day exploited in attacks
Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users. [...]
AI Analysis
Technical Summary
CVE-2026-42897 is a high-severity cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016, 2019, and Subscription Edition. It allows remote attackers to execute arbitrary JavaScript code in the context of Outlook Web Access by sending a specially crafted email. The vulnerability was actively exploited before patching. Microsoft initially deployed an automatic temporary mitigation via the Exchange Emergency Mitigation Service (EEMS) and later released official security updates in June 2026. The vendor strongly advises applying these updates promptly and retaining the mitigation to ensure continuous protection. The U.S. CISA added this vulnerability to its exploited-in-the-wild list and required government agencies to patch quickly. This vulnerability requires no privileges and can be triggered by user interaction with a malicious email in Outlook Web Access.
Potential Impact
The vulnerability enables remote attackers to execute arbitrary JavaScript code in the browser of Outlook Web Access users, potentially leading to spoofing and other XSS-related impacts. Because exploitation requires no privileges and only user interaction with a crafted email, the risk of compromise is significant for affected Exchange Server environments. The vulnerability was actively exploited in the wild prior to patching, increasing the urgency of remediation. The impact is limited to Outlook Web Access users on affected Exchange Server versions.
Mitigation Recommendations
Microsoft has released official security updates for Exchange Server 2016, 2019, and Subscription Edition to address this vulnerability. Administrators should deploy these June 2026 security updates as soon as possible. Additionally, Microsoft recommends maintaining the previously deployed Exchange Emergency Mitigation Service (EEMS) temporary mitigation to provide an additional layer of defense. No further action beyond applying the patch and retaining the mitigation is indicated by the vendor.
Microsoft patches Exchange Server zero-day exploited in attacks
Description
Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users. [...]
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-42897 is a high-severity cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016, 2019, and Subscription Edition. It allows remote attackers to execute arbitrary JavaScript code in the context of Outlook Web Access by sending a specially crafted email. The vulnerability was actively exploited before patching. Microsoft initially deployed an automatic temporary mitigation via the Exchange Emergency Mitigation Service (EEMS) and later released official security updates in June 2026. The vendor strongly advises applying these updates promptly and retaining the mitigation to ensure continuous protection. The U.S. CISA added this vulnerability to its exploited-in-the-wild list and required government agencies to patch quickly. This vulnerability requires no privileges and can be triggered by user interaction with a malicious email in Outlook Web Access.
Potential Impact
The vulnerability enables remote attackers to execute arbitrary JavaScript code in the browser of Outlook Web Access users, potentially leading to spoofing and other XSS-related impacts. Because exploitation requires no privileges and only user interaction with a crafted email, the risk of compromise is significant for affected Exchange Server environments. The vulnerability was actively exploited in the wild prior to patching, increasing the urgency of remediation. The impact is limited to Outlook Web Access users on affected Exchange Server versions.
Mitigation Recommendations
Microsoft has released official security updates for Exchange Server 2016, 2019, and Subscription Edition to address this vulnerability. Administrators should deploy these June 2026 security updates as soon as possible. Additionally, Microsoft recommends maintaining the previously deployed Exchange Emergency Mitigation Service (EEMS) temporary mitigation to provide an additional layer of defense. No further action beyond applying the patch and retaining the mitigation is indicated by the vendor.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-exchange-server-zero-day-exploited-in-attacks/","fetched":true,"fetchedAt":"2026-06-10T13:49:44.312Z","wordCount":664}
Threat ID: 6a296b78c9170919df24460a
Added to database: 6/10/2026, 1:49:44 PM
Last enriched: 6/10/2026, 1:49:51 PM
Last updated: 6/10/2026, 7:29:24 PM
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.