Exchange vulnerability actively exploited through crafted email in OWA
Microsoft has disclosed CVE-2026-42897, a vulnerability affecting on-premises Exchange Server installations, and confirmed it is being actively exploited. According to Microsoft, attackers can exploit the flaw by sending a specially crafted email to a user of Outlook Web Access. If the message is opened and certain interaction conditions are met, arbitrary JavaScript can execute within the victim's browser session.
The issue affects Exchange Server 2016, 2019 and Subscription Edition. Exchange Online is not impacted. Microsoft has released mitigations and urges organisations to apply updates immediately.
What this means for your business
The attack requires nothing more from the victim than opening an email in a browser, which the entire organisation does every day. Organisations still running Exchange themselves, often justified by data location or integrations, now hold an actively exploited vulnerability in their most exposed service. This is a good moment to raise the question of continued self-hosted Exchange at management level.
Berigo recommends
- Install the update for Exchange Server 2016, 2019 and Subscription Edition without waiting for the next maintenance window.
- Assess whether OWA needs to be open to the internet, or whether access can be limited to known networks and devices.
- Review logs for signs of exploitation in the period before the update was installed.
- Present to management what continuing with self-hosted Exchange costs, measured against the alternatives.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch