CTIPilot

Microsoft Exchange Server Outlook Web Access stored XSS (CWE-79, CVSS 3.1 8.1, Microsoft CNA), exploited in the wild by TA488/LAUNDRY BEAR to deliver the OWAReaper browser implant; CISA KEV 2026-05-15; permanent fix is the July 2026 Exchange SU (SE RTM; 2019 CU14/CU15 and 2016 CU23 via ESU Period 2), which does not remove earlier mitigations

cve · CVE-2026-42897

Coverage timeline
4
first 2026-05-16 → last 2026-08-02
Peak priority
critical
2 critical · 2 notable
Sources cited
20
12 hosts
Sections touched
2
deep-dive, trending-vulnerabilities
Co-occurring entities
5
see Co-occurring entities below
ATT&CK techniques
14
pinned v19.2 · see below

ATT&CK techniques

14 techniques observed across 2 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou · ATT&CK page ↗

T1566Phishing×2

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou · ATT&CK page ↗

T1566.001Phishing: Spearphishing Attachment×1

Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou · ATT&CK page ↗

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou · ATT&CK page ↗

T1203Exploitation for Client Execution×1

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou · ATT&CK page ↗

T1098.002Account Manipulation: Additional Email Delegate Permissions×1

Adversaries may grant additional permission levels to maintain persistent access to an adversary-controlled email account.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou · ATT&CK page ↗

T1098.002Account Manipulation: Additional Email Delegate Permissions×1

Adversaries may grant additional permission levels to maintain persistent access to an adversary-controlled email account.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou · ATT&CK page ↗

Credential Access TA0006

T1552Unsecured Credentials×1

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

Lateral Movement TA0008

T1534Internal Spearphishing×1

After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization. Internal spearphishing is multi-staged campaign where a legitimate account is initially compromised either by controlling the user's device or by compromising the account credentials of the user. Adversaries may then attempt to take advantage of the trusted internal account to increase the likelihood of tricking more victims into falling for phish attempts, often incorporating Impersonation.

Evidence: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou · ATT&CK page ↗

Collection TA0009

T1185Browser Session Hijacking×2

Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking techniques.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

T1071.004Application Layer Protocol: DNS×1

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

T1102.001Web Service: Dead Drop Resolver×1

Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

Story timeline

  1. 2026-05-18CVE-2026-42897 Exchange OWA, EM Service auto-mitigation depends on outbound connectivity to officemitigations.microsoft.com
    trending-vulnerabilities
  2. 2026-05-17Exchange CVE-2026-42897, Pwn2Own DEVCORE three-bug SYSTEM RCE chain emerges alongside active OWA-XSS exploitation
    trending-vulnerabilities
  3. 2026-05-16Microsoft Exchange CVE-2026-42897: Active Exploitation Without a Patch
    deep-dive
  4. 2026-05-16CVE-2026-42897, Microsoft Exchange Server 2016 / 2019 / SE: stored XSS in OWA, actively exploited, no permanent patch
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities3
  • deep-dive1

Source distribution

  • attack.mitre.org5 (25%)
  • techcommunity.microsoft.com3 (15%)
  • cisa.gov2 (10%)
  • msrc.microsoft.com2 (10%)
  • advisories.ncsc.nl1 (5%)
  • bleepingcomputer.com1 (5%)
  • microsoft.com1 (5%)
  • proofpoint.com1 (5%)
  • other4 (20%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

External references

NVD · cve.org · CISA KEV

All cited sources (20)

Entries about Microsoft Exchange Server Outlook Web Access stored XSS (CWE-79, CVSS 3.1 8.1, Microsoft CNA), exploited in the wild by TA488/LAUNDRY BEAR to deliver the OWAReaper browser implant; CISA KEV 2026-05-15; permanent fix is the July 2026 Exchange SU (SE RTM; 2019 CU14/CU15 and 2016 CU23 via ESU Period 2), which does not remove earlier mitigations (4)

2026-05-18 · view entry permalink →

CRITICALCVE-2026-42897exploitedupdatedNATOA1

CVE-2026-42897 Exchange OWA, EM Service auto-mitigation depends on outbound connectivity to officemitigations.microsoft.com

UPDATE (originally covered 2026-05-15 / deep-dive 2026-05-16): The Microsoft Exchange Team Blog post addressing CVE-2026-42897 was last modified 2026-05-17 to clarify an operational dependency that defenders must verify on every Exchange Mailbox host: the Exchange Emergency Mitigation Service (EM Service / EEMS) (which auto-applies the URL-Rewrite mitigation labelled M2.1.x) only delivers that mitigation when it can reach officemitigations.microsoft.com over outbound HTTPS. Segmented on-premises Exchange 2016 / 2019 / Subscription-Edition deployments that block direct outbound HTTPS from the Mailbox role will therefore not have received the automatic mitigation and remain exposed to the actively-exploited OWA stored-XSS chain.

The CVE remains CISA KEV-listed (added 2026-05-15) with no permanent cumulative-update fix as of 2026-05-18; Microsoft states verbatim "We are working on developing and testing a more permanent fix which we will provide when it meets our quality standards." Exchange Online is unaffected. Operational verification per server: Get-ExchangeDiagnosticInfo -Server <server> -Process EdgeTransport -Component EmergencyMitigation returns Status: Active and rule M2.1.x applied; manual application on hosts that cannot reach the mitigation service: .\EOMT.ps1 -CVE "CVE-2026-42897" from an elevated Exchange Management Shell, or apply the documented URL Rewrite rule by hand.

The Exchange Emergency Mitigation Service will provide mitigation automatically, and is on by default. If it is not already enabled on your Exchange Server, you need to enable Exchange Emergency Mitigation Service.

We are working on developing and testing a more permanent fix which we will provide when it meets our quality standards.

Microsoft Exchange Team Blog 2026-07-14

The messages exploit CVE-2026-42897, a vulnerability in Outlook Web Access in which the server does not adequately sanitize HTML in the message body. This allows a loader piece of JavaScript to use the onload= event handler to parse the rest of the message body, assemble a Base64 fragment, and execute it as encoded JavaScript.

This persistent access lives on the server-side and requires deliberate removal from the Exchange server; credential rotation and even full re-imaging of the targeted user's device will not evict the actor.

Proofpoint 2026-07-29

Installing the July 2026 update does not automatically remove already applied CVE-2026-42897 mitigations.

Microsoft Exchange Team Blog 2026-07-14
Updaterun 2026-07-31T0409Z-intelactionsaffected_productscvesentitiesevidencereferencesregionssectorssourcestagstechniquesbody

The May entry tracked CVE-2026-42897 as an Exchange OWA flaw whose interim protection depended on the EM Service auto-mitigation. Two things changed. Proofpoint has now attributed in-the-wild exploitation to a named Russian state-supported actor and published the implant's full mechanics (Proofpoint, 2026-07-29), and the mitigation is no longer the remediation; the July 2026 Security Update is, with the mitigation now something that must be actively torn down (Microsoft Exchange Team Blog, 2026-07-14). NCSC-CH appended the Proofpoint reporting to its own advisory on 2026-07-30 (NCSC Switzerland, 2026-07-30).

The actor is TA488, which Microsoft tracks as Void Blizzard and which this pipeline registers as LAUNDRY BEAR, the same Russian state-supported email-espionage actor a 16-nation joint advisory exposed on 2026-07-23 for its Zimbra campaign. Proofpoint assesses OWAReaper as an evolution of that campaign's ZimReaper payload, citing shared code including an identical invisible-element sizing and error-handling pattern (Proofpoint, 2026-07-29). Campaign activity began 2026-07-22 against government, telecommunications, finance, hospitality and aerospace targets across the US and Europe, using deliberately banal lure subjects with no call to action, Proofpoint reads the unusual breadth as intentional blending with bulk mail. Its stated infrastructure-creation date of March 2026 precedes Microsoft's May disclosure by two months, which is the basis for its assessment that zero-day use is feasible; that is an inference from infrastructure dating, not a confirmed finding.

Execution. The flaw is a failure to sanitise HTML in the message body, so a loader script in an onload= handler reassembles a Base64 fragment from the rest of the message and evaluates it, no link click and no attachment open, only viewing the message in OWA. The exploit and payload fragments are hidden inside the message's social-media icon elements, with next-stage data placed after # fragment markers where the browser's Base64 image parser stops reading, so the payload is not visible to casual inspection of the HTML. On execution OWAReaper first rewrites the delivered message server-side to strip the exploit content and suppresses OWA pop-ups and right-click, then enumerates the victim's address, username and settings.

Credential and token theft. It creates two invisible input elements and waits for the browser's own autofill to populate them with the saved OWA username and password. Separately it enumerates installed Outlook add-ins holding ReadWriteMailbox permission and, where one exists, abuses it to call GetClientAccessToken and obtain OAuth tokens.

Persistence, in three independent layers. Client-side, the implant writes an AES-encrypted copy of itself and a decryption wrapper into browser localStorage under a settings field of the legitimate PageDataPayload.OwaUserDefaultSettings key, which OWA itself evaluates during its own sync-restore flow, so every ordinary OWA tab-open re-launches it with no separate loader. A second client-side layer adds a hidden iframe to messages cached in OWA's offline IndexedDB store, so opening the cached message re-infects an endpoint even after a full re-image. The third is server-side and is the one that matters most: the implant calls UpdateFolder to grant Owner-level permission on every mail folder to the low-privilege "Default" preset alias that exists in every Exchange organisation. Proofpoint is explicit that this "requires deliberate removal from the Exchange server" and that credential rotation and re-imaging will not evict it.

Command and control. Two channels, both over infrastructure defenders generally trust. The implant polls GitHub's public Commit Search API every 24 hours for crafted commit messages containing the target's own email address, decrypting matches to a four-character command header that selects toolkit replacement, C2-domain rotation, or one-off code execution; in parallel it re-parses cached inbound messages every five minutes for the same command structure. Exfiltration runs primarily over HTTPS with encrypted URI paths, either relayed through a set of legitimate image-CDN domains or sent directly to the actor-controlled server when those proxies fail; if the HTTPS method fails altogether, the implant switches to DNS label tunnelling, packing the data into the subdomain labels of ordinary DNS queries for an actor-controlled domain. Notably, Proofpoint states there is no mass mailbox exfiltration here, unlike the Zimbra campaign, which is why this entry maps browser-session and credential-access behaviour rather than bulk email collection.

Patching. The permanent fix is the July 2026 Security Update, available as Exchange SE RTM publicly and for Exchange 2019 CU14/CU15 and Exchange 2016 CU23 only through the Period 2 Extended Security Update programme; organisations that were enrolled only in Period 1, which ended in April 2026, do not receive it (Microsoft Exchange Team Blog, 2026-07-14). Microsoft's own vulnerability record scores the flaw 8.1 and marks it exploited (Microsoft Security Response Center, 2026-07-14). Installing the update does not remove a previously applied mitigation: administrators who used the EM Service must remove the M2.1.0 IIS rules through the documented rollback, and those who ran the downloadable mitigation script must run its rollback. The known operational side effects of the mitigation era (broken OWA calendar printing, inline-image rendering problems, OWA-light failing, and false-unhealthy calendar-proxy health alerts) only clear once both steps are done, so a server left on mitigation-only status keeps them indefinitely (Microsoft Exchange Team Blog, 2026-05-14).

Detection. The highest-value signal is in mailbox audit and Exchange Web Services telemetry: a folder-permission change granting Owner rights to the "Default" alias, applied across many folders of one mailbox in quick succession. Client-side, monitor for writes to the OWA user-default-settings localStorage key outside the browser's own sync flow, and for OWA sessions in which invisible form inputs are created and immediately populated. On the network side, two egress patterns stand out from a mail client's normal behaviour: repeated polling of a public source-code hosting search API on a roughly daily cadence, and DNS queries with the label-length and entropy profile of tunnelled data.

Triage: OWA legitimately reads and writes its own settings keys constantly, so the presence of localStorage activity is not the signal; the discriminator is the specific settings-field path carrying an encrypted blob, and its correlation with a message open. For the server-side artifact the discrimination is cleaner: administrators do grant folder permissions, but they grant them to named users or groups for a specific folder, not Owner rights to the built-in "Default" alias across an entire mailbox. Treat any such grant as compromise until proven otherwise.

Improvementrun 2026-08-30T1312Z-auditactionsclassification

This entry now carries a source-reliability rating, which it predates: A1 on the NATO Admiralty scale. The letter reflects Microsoft's own advisory for its own product, the number reflects independent corroboration, since Proofpoint analysed the implant separately from Microsoft's disclosure and NCSC-CH restated that analysis for its own constituency. Nothing in the assessment or the remediation guidance changes; the rating makes explicit what the sourcing already supported.

Builds on: 2026-07-24/laundry-bear-zimbra-zero-click-cve-2025-66376

vulnerability18 May 05:00Zmulti-sourceOpen finding ↗

2026-05-17 · view entry permalink →

NOTABLECVE-2026-42897exploited

Exchange CVE-2026-42897, Pwn2Own DEVCORE three-bug SYSTEM RCE chain emerges alongside active OWA-XSS exploitation

UPDATE (originally covered 2026-05-15 and 2026-05-16 deep dive): DEVCORE's Orange Tsai chained three undisclosed Exchange Server bugs on Pwn2Own Berlin 2026 Day 2 to achieve unauthenticated remote code execution at SYSTEM privilege level, earning $200,000 (Zero Day Initiative, 2026-05-15; BleepingComputer, 2026-05-15). This chain is separate from the actively-exploited CVE-2026-42897 (OWA stored XSS, no permanent patch; EEMS mitigation M2.1.x only) that the 2026-05-16 deep dive covered. ZDI verbatim: "Orange Tsai (DEVCORE Research Team) earned $200,000 after chaining three bugs to gain remote code execution with SYSTEM privileges on Microsoft Exchange."

The three bugs are under a 90-day Pwn2Own embargo; Microsoft must patch by approximately 2026-08-14 before ZDI publishes technical detail. Operationally, the compound risk for on-premises Exchange has materially worsened in 48 h: one actively exploited XSS without a permanent patch (M2 mitigation only, with known OWA Calendar Print / inline-image side-effects), plus a fresh unauthenticated SYSTEM RCE class that defenders cannot pre-emptively patch. CVE-2026-42897 remains in CISA KEV (added 2026-05-15) with EEMS as the only listed mitigation; the Microsoft Exchange blog post addressing-exchange-server-may-2026-vulnerability-cve-2026-42897 linked from the MSRC advisory returns 502 on direct fetch and the MSRC entry itself is the operational primary (MSRC CVE-2026-42897).

Defender response shift for on-premises Exchange 2016/2019/SE: treat the platform as severely threatened. Verify EEMS service is enabled (Get-ExchangeDiagnosticInfo, mitigation M2.1.x present in applied list); restrict ECP/EWS/OWA reachability from the internet at the WAF or reverse proxy where business-feasible; accelerate any in-progress Exchange Online migration; assume hypothetical compromise paths through both OWA-browser-context attacks (CVE-2026-42897) and a direct service-account SYSTEM RCE chain (Pwn2Own DEVCORE) until Microsoft ships permanent fixes for both. Exchange Online tenants are not in scope for either.

UPDATE (originally covered 2026-05-15 and 2026-05-16 deep dive): DEVCORE's Orange Tsai chained three undisclosed Exchange Server bugs on Pwn2Own Berlin 2026 Day 2 to achieve unauthenticated remote code execution at SYSTEM privilege level, earning $200,000 (Zero Day Initiative, 2026-05-15 …

ctipilot v2 brief (migrated)
vulnerability17 May 05:00Zmulti-sourceOpen finding ↗

2026-05-16 · view entry permalink →

NOTABLECVE-2026-42897exploited

Microsoft Exchange CVE-2026-42897: Active Exploitation Without a Patch

Background. On-premises Microsoft Exchange has been a sustained, high-value target for advanced and opportunistic actors for the entire 2021–2026 window. ProxyLogon (CVE-2021-26855 + chain) in March 2021 was exploited at scale by Hafnium and dozens of follow-on clusters before mitigations stuck; ProxyShell (CVE-2021-34473 + chain) repeated the pattern in August 2021 (Microsoft Threat Intelligence, 2021-03-02 · CISA Alert AA21-321A, 2021-11-17). The Exchange Emergency Mitigation Service (EEMS), introduced in Exchange Server 2016 CU22 and 2019 CU11, was Microsoft's explicit response to that pattern: a small auto-update mechanism that ships URL-rewrite rules to live Exchange front-ends in the gap between an in-the-wild zero-day and a permanent CU (Microsoft, 2021-09-28). CVE-2026-42897 is the first 2026 case where EEMS (not a Patch Tuesday CU) is the line of defence against active exploitation; the deep dive that follows is therefore as much about EEMS verification and bypass conditions as about the XSS itself.

Vulnerability mechanics. CVE-2026-42897 is classified by Microsoft as a spoofing vulnerability (impact category) underpinned by CWE-79, improper neutralisation of input during web-page generation, in the Outlook Web Access (OWA) component (Microsoft MSRC, 2026-05-14). The CVSS:3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N describes a network-deliverable XSS that requires the victim to open the malicious message in OWA: no authentication is required of the attacker, only of the recipient. Microsoft assesses severity Critical despite the 8.1 base score, the "Critical" label reflects the impact reach (session-token theft, content tampering in the OWA session, downstream phishing from a now-trusted internal mailbox), not the base metric. Microsoft has not published the precise attacker-controlled fragment that delivers the JavaScript payload (consistent with Exploitation Detected status, the team is withholding payload format pending the permanent SU) but the MSRC FAQ confirms the chain shape: crafted email → OWA render → script execution → spoofing actions taken under the victim's authenticated OWA context. Affected versions are Exchange Server 2016 (all CU levels), Exchange Server 2019 (all CU levels), and Exchange Server Subscription Edition (RTM and current CUs); Exchange Online is unaffected.

Exploitation status and attribution. Microsoft confirmed Exploitation Detected on 2026-05-14 with the published advisory (Microsoft MSRC, 2026-05-14). The NCSC Switzerland Cyber Security Hub independently restated the active-exploitation finding in advisory #12577 on 2026-05-15 (NCSC-CH Security Hub #12577, 2026-05-15). CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2026-05-15 with a federal civilian-branch remediation deadline of 2026-05-29; per PD-13 in this brief series, that deadline has no jurisdictional weight in Switzerland or the EU and is recorded here only as confirmation of the exploitation signal; defenders should drive the remediation timeline off the Microsoft-confirmed active exploitation, not the BOD 22-01 date. No named threat-actor attribution has been published; Microsoft notes the scale and identity of the exploitation activity are not yet detailed publicly (The Hacker News, 2026-05-15).

Attack chain. From the limited disclosure, the operationally credible kill chain is:

  1. T1566.001 Phishing: Spearphishing Attachment: attacker delivers a specifically crafted email to a target whose mailbox is hosted on a vulnerable on-premises Exchange Server.
  2. T1059.007 Command and Scripting Interpreter: JavaScript: when the target opens the message in OWA, browser-side JavaScript executes in the OWA origin's context.
  3. T1185 Browser Session Hijacking: payload reads OWA session cookies / auth tokens and exfiltrates to attacker-controlled infrastructure.
  4. T1078 Valid Accounts: attacker re-uses the exfiltrated session material to issue authenticated OWA requests as the victim, with full mailbox read/send privileges.
  5. T1534 Internal Spearphishing: onward phishing from the now-trusted internal sender to high-value recipients (executives, finance, identity admins), spreading the access.

EEMS; what it does, when it doesn't apply. The Exchange Emergency Mitigation Service is a small Windows service installed by the Exchange setup process on Exchange 2016 CU22 / Exchange 2019 CU11 and later; it polls a Microsoft-hosted Office Config Service endpoint hourly for new mitigation rules and applies URL-rewrite rules to the IIS configuration when one matches the server's installed Exchange version. For CVE-2026-42897, Microsoft has published Mitigation M2, which rewrites the specific request format the in-the-wild exploit uses to deliver the XSS payload; the mitigation does not require an Exchange restart and applies automatically on any internet-connected, EEMS-enabled Exchange server (Microsoft Exchange Team, 2026-05-14). EEMS does not apply automatically in the following operationally common configurations: (a) Exchange Server 2013, on which EEMS is not available; (b) Exchange servers with no outbound HTTPS connectivity to officeclient.microsoft.com (air-gapped networks, segmented DMZs, environments with strict egress controls); (c) Exchange servers where EEMS has been manually disabled (Set-OrganizationConfig -MitigationsEnabled $false, Set-Server -MitigationsEnabled $false, or via Group Policy); (d) Exchange servers that have been hardened with custom IIS rewrite rules that conflict with the EEMS rule placement. For all four cases, operators must run the Exchange On-Premises Mitigation Tool (EOMT) (downloadable from aka.ms/UnifiedEOMT) via the Exchange Management Shell as Administrator, which applies the same URL-rewrite Mitigation M2 manually.

EEMS verification; what to actually run on every Exchange server. The canonical check is:

  • Get-ExchangeDiagnosticInfo -Server <server> -Process MSExchangeHMWorker -Component EemsMitigation -SettingName MitigationsApplied and confirm the Mitigation M2 identifier published in the MSRC advisory appears in the output.
  • Get-OrganizationConfig | Select-Object MitigationsEnabled and Get-Server <server> | Select-Object MitigationsEnabled should both return True.
  • IIS Manager → Default Web Site → URL Rewrite should show the EEMS-injected rewrite rule corresponding to CVE-2026-42897.

If any check fails, run EOMT immediately; do not wait for the next EEMS poll cycle.

Permanent-patch availability, the Period 2 ESU constraint. Microsoft has signalled that the permanent fix will ship as a CU for Exchange Server Subscription Edition (publicly available SU) and as a security update for Exchange 2016 CU23 and Exchange 2019 CU14 / CU15, but the Exchange 2016 / 2019 updates will only be distributed to organisations enrolled in the Period 2 Exchange Server Extended Security Update programme (Microsoft Exchange Team, 2026-05-14). Any Swiss or European public-sector organisation running Exchange 2016 / 2019 in production today should verify ESU enrolment status with its Microsoft licensing partner before relying on the permanent update path; organisations that are not enrolled face a structural constraint where EEMS Mitigation M2 is the permanent operational mitigation, not the bridge.

Hunt and detection concepts. The mitigation prevents future exploitation; it does not retroactively detect or remediate prior exploitation. Defenders should look back to 2026-05-09 (a generous overlap window prior to public disclosure):

  • IIS access logs (front-end Exchange role): /owa/ URLs with <script>, javascript:, or HTML-encoded equivalents in query strings; OWA URLs with anomalous referrer headers from external mail-rendering paths.
  • Exchange transport logs: emails with HTML bodies that embed encoded JavaScript fragments delivered to mailboxes whose owners are OWA users (cross-correlate with Get-CASMailbox -OWAEnabled $true).
  • EDR telemetry on Exchange front-end servers: w3wp.exe (IIS worker process, Exchange app pool) spawning unexpected children (cmd.exe, powershell.exe, cscript.exe, browser launchers) is the post-exploitation tell of XSS-to-execution chains observed in prior Exchange compromises.
  • Exchange Application Event Log EID 4 (MSExchange Management): for EEMS mitigation-state changes; flag any disable / re-enable cycle that does not correspond to a documented change.
  • OWA session anomalies: Get-MailboxAuditLog for unusual mailbox-folder reads or message-send activity from sessions whose source IP differs from the user's established pattern.

Hardening and mitigation. The non-negotiable immediate action is verifying EEMS Mitigation M2 is applied on every Exchange Server 2016, 2019, and SE in the estate and applying EOMT where it is not. Beyond that, defenders should: (a) confirm Period 2 ESU enrolment for any Exchange 2016 / 2019 production deployment that is not on a migration path to SE or Online; (b) restrict OWA access at the perimeter to users behind Conditional Access compliant-device policy where possible, reducing the population of XSS-deliverable mailboxes; (c) plan migration to Exchange Server SE or Exchange Online; repeated EEMS-only mitigations across the 2021–2026 Exchange CVE history are the operational signal that on-premises Exchange has become structurally expensive to defend on the 2016 / 2019 codebases.

Background.

ctipilot v2 brief (migrated)
vulnerability16 May 05:00Zmulti-sourceOpen finding ↗

Earlier coverage (1)