Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

PFAS monitoring permanently detects chemicals in all rain and snow samples across the Great Lakes

AI-informed integration of electric vehicles charging infrastructure for resilient distribution grids

On-premises Microsoft Exchange Server CVE-2026-42897 can be exploited via crafted email

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » On-premises Microsoft Exchange Server CVE-2026-42897 can be exploited via crafted email
Identity

On-premises Microsoft Exchange Server CVE-2026-42897 can be exploited via crafted email

By May 15, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rabi LakshmananMay 15, 2026Microsoft / Vulnerability

Microsoft has disclosed a new security vulnerability affecting the on-premises version of Exchange Server and announced that it is being exploited in the wild.

The vulnerability is tracked as CVE-2026-42897 (CVSS score: 8.1) and is described as a spoofing bug due to a cross-site scripting flaw. An anonymous researcher is credited with discovering and reporting this issue.

“Inappropriate neutralization of input during web page generation (‘cross-site scripting’) in Microsoft Exchange Server could allow an unauthorized attacker to perform spoofing on your network,” the tech giant said in an advisory Thursday.

Microsoft, which has rated the vulnerability as “Exploit Detected,” said that an attacker could weaponize the vulnerability by sending a crafted email to a user, which, if opened in Outlook Web Access and subject to other “specific interaction conditions,” could result in arbitrary JavaScript code being executed in the context of the web browser.

Redmond also noted that while it provides temporary mitigation through the Exchange Emergency Mitigation Service, it is preparing permanent fixes for the security flaws.

Exchange Emergency Mitigation Service automatically provides mitigation through URL rewriting configuration and is enabled by default. Since it is not turned on, we recommend that you enable Windows Services.

According to Microsoft, Exchange Online is not affected by this vulnerability. The following on-premises Exchange Server versions are affected:

Exchange Server 2016 (any update level) Exchange Server 2019 (any update level) Exchange Server Subscription Edition (SE) (any update level)

If using the Exchange Emergency Mitigation Service is not an option due to air-gap limitations, the company outlines the next course of action.

Download the latest version of Exchange On-Premises Mitigation Tools (EOMT) from alias.[.]Milliseconds/UnifiedEOMT. Apply the mitigation on a server-by-server basis, or run a script through an elevated Exchange Management Shell (EMS) to apply the mitigation on all servers at once. Single server: .\EOMT.ps1 -CVE “CVE-2026-42897” All servers: Get-ExchangeServer | Where-Object { $_.ServerRole -ne “Edge” } | .\EOMT.ps1 -CVE “CVE-2026-42897”

Microsoft said it is also aware of a known issue where the mitigation description field displays “Mitigation is disabled for this Exchange version.” “This issue is cosmetic and the mitigation will be applied successfully if the status shows ‘Applied’,” the Exchange team said. “We are considering ways to respond.”

At this time, details about how this vulnerability is exploited, the identity of the threat actor behind the activity, or its scale are unknown. It’s also unclear who the targets were and whether those attacks were successful. In the meantime, we recommend applying the mitigations recommended by Microsoft.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCISA adds Cisco SD-WAN CVE-2026-20182 to KEV after administrator access exploit
Next Article AI-informed integration of electric vehicles charging infrastructure for resilient distribution grids

Related Posts

CISA adds Cisco SD-WAN CVE-2026-20182 to KEV after administrator access exploit

May 15, 2026

Cisco Catalyst SD-WAN Controller Authentication Bypass Is Actively Abused to Gain Administrative Access

May 14, 2026

Stealer backdoor targeting developer secrets found in three node IPC versions

May 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

PFAS monitoring permanently detects chemicals in all rain and snow samples across the Great Lakes

AI-informed integration of electric vehicles charging infrastructure for resilient distribution grids

On-premises Microsoft Exchange Server CVE-2026-42897 can be exploited via crafted email

CISA adds Cisco SD-WAN CVE-2026-20182 to KEV after administrator access exploit

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.