Microsoft Exchange Server Vulnerability CVE-2026-42897: Spoofing Bug from XSS Exploited in Wild
Patch Exchange Server to fix CVE‑2026‑42897 immediately.
Patch Exchange Server immediately to address CVE‑2026‑42897.
Summary
Microsoft has disclosed a new security vulnerability affecting on‑premises versions of Exchange Server, identified as CVE-2026-42897. The flaw is a spoofing bug stemming from a cross‑site scripting (XSS) vulnerability, with a CVSS score of 8.1. An anonymous researcher discovered and reported the issue, and the vulnerability has already been exploited in the wild. The XSS flaw allows attackers to inject malicious scripts that can spoof user identities within the Exchange interface. The vulnerability affects all on‑prem Exchange deployments that have not applied the latest patch. Microsoft recommends applying the Exchange Server patch immediately to mitigate the risk. The active exploitation underscores the urgency of addressing the flaw. The patch addresses the XSS code path in the Exchange web client. Users should verify that their Exchange servers are up to date.
Key changes
- CVE‑2026‑42897 is a spoofing bug from XSS.
- Affects on‑prem Exchange Server.
- CVSS 8.1.
- Active exploitation in wild.
- XSS allows identity spoofing in Exchange web client.
- Affects all on‑prem Exchange deployments lacking patch.
- Microsoft recommends patching immediately.
- Patch addresses XSS code path.