---
schema: 1
kind: vulnerability
title: "CVE-2026-42897 — Microsoft Exchange Server 2016 / 2019 / SE: stored XSS in OWA, actively exploited, no permanent patch"
headline: "CVE-2026-42897 — Microsoft Exchange Server 2016 / 2019 / SE: stored XSS in OWA, actively exploited, no permanent patch"
summary: "Microsoft Exchange Server CVE-2026-42897 (CVSS 8.1) actively exploited via crafted-email XSS in OWA; CISA KEV-added 2026-05-15; no permanent patch — only EEMS auto-mitigation; air-gapped servers need EOMT manual install; Exchange 2016/2019 permanent fix gated behind Period 2 ESU enrolment (Microsoft MSRC, 2026-05-14 · NCSC-CH Security Hub #12577, 2026-05-15)."
discovered_at: "2026-05-16T05:00:04Z"
event_date: 2026-05-15
run_id: 2026-05-16-5bc123a0
priority: critical
immediate_action:
  title: "Verify EEMS Mitigation M2 deployed on every on-premises Exchange Server 2016 / 2019 / SE; deploy EOMT manually on air-gapped Exchange"
  action: "CVE-2026-42897 is a CVSS 8.1 stored XSS in Outlook Web Access that is actively exploited in the wild as of 2026-05-14, with no permanent patch — Microsoft has confirmed Exploitation Detected and is shipping only a temporary URL-rewrite mitigation through the Exchange Emergency Mitigation Service."
tags:
  - vulnerabilities
  - actively-exploited
  - cisa-kev
  - no-patch
regions:
  - global
sectors:
  - public-sector
  - healthcare
  - education
  - finance
entities: []
cves:
  - id: CVE-2026-42897
    cvss: "8.1"
    epss: null
    type: null
    vector: user-interaction
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - mitigation-only
sources:
  - url: "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897"
    publisher: "Microsoft MSRC, 2026-05-14"
    role: primary
  - url: "https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498"
    publisher: "Microsoft Exchange Team, 2026-05-14"
    role: corroborating
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12577"
    publisher: "NCSC-CH Security Hub #12577, 2026-05-15"
    role: corroborating
  - url: "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1536"
    publisher: "BSI WID-SEC-2026-1536, 2026-05-14"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Current exploitation status: Actively Exploited"
    publisher: NCSC Switzerland Cyber Security Hub
  - quote: Microsoft is supplying a temporary mitigation for this vulnerability through the Exchange Emergency Mitigation Service. We are working on developing and testing a more permanent fix.
    publisher: Microsoft MSRC
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Verify EEMS Mitigation M2 deployed on every on-premises Exchange Server 2016 / 2019 / SE — and apply EOMT manually on air-gapped / EEMS-disconnected / hardened servers.** CVE-2026-42897 is actively exploited with no permanent patch; EEMS auto-applies the URL-rewrite mitigation only on Exchange 2016 SP1+ with outbound HTTPS to `officeclient.microsoft.com`. Run `Get-ExchangeDiagnosticInfo -Server <name> -Process MSExchangeHMWorker -Component EemsMitigation -SettingName MitigationsApplied` on every Exchange server; where the M2 identifier is absent, download and execute EOMT from `aka.ms/UnifiedEOMT` as Administrator. Then look back to 2026-05-09 in IIS access logs on the front-end Exchange role for `/owa/` URLs with script-injection payloads — EEMS prevents future exploitation, not prior."
  - "**Confirm Period 2 Exchange Server Extended Security Update enrolment for any Exchange 2016 / 2019 production deployment.** The permanent CVE-2026-42897 fix for Exchange 2016 / 2019 will be distributed only to Period 2 ESU-enrolled organisations; Exchange SE will receive a publicly available SU. CH/EU public-sector organisations on Exchange 2016 / 2019 should verify ESU enrolment status with their Microsoft licensing partner this week — and where enrolment is not in place, treat EEMS Mitigation M2 as the permanent operational control until migration to Exchange SE or Exchange Online completes. See § 5 (Deep Dive, \"Permanent-patch availability\" paragraph)."
migrated_from: briefs/2026-05-16.md
---

CVE-2026-42897 (CWE-79, CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N, base 8.1) is a stored / reflected cross-site scripting flaw in the Outlook Web Access component of on-premises Microsoft Exchange Server, disclosed by Microsoft on 2026-05-14 alongside the May 2026 Patch Tuesday cycle ([Microsoft MSRC, 2026-05-14](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897) · [Microsoft Exchange Team, 2026-05-14](https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498) · [NCSC-CH Security Hub #12577, 2026-05-15](https://security-hub.ncsc.admin.ch/#/posts/12577) · [BSI WID-SEC-2026-1536, 2026-05-14](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1536) · [NCSC-NL NCSC-2026-0159, 2026-05-15](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0159)). An unauthenticated attacker delivers a specially crafted email; when the recipient opens it in OWA and a documented set of interaction conditions are met, arbitrary JavaScript executes in the OWA browser context — yielding session-token theft, content spoofing, and onward lateral phishing from the now-trusted sender. Microsoft has confirmed `Exploitation Detected` (the highest of its three exploitation-status tiers) and assesses the issue as Critical despite the 8.1 base score; CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2026-05-15 with a federal remediation deadline of 2026-05-29. Affected: Exchange Server 2016 (all CU levels), Exchange Server 2019 (all CU levels), Exchange Server Subscription Edition (RTM and current CUs). Exchange Online is **not** affected. **There is no permanent patch in the May 2026 Patch Tuesday bundle.** Microsoft is shipping only an interim URL-rewrite Mitigation M2 through the Exchange Emergency Mitigation Service (EEMS), which is enabled by default on Exchange 2016 SP1 and later and auto-applies without requiring a service restart; air-gapped or EEMS-disconnected servers, plus deployments where EEMS has been manually disabled, must apply Mitigation M2 by running the Exchange On-Premises Mitigation Tool (EOMT) script from `aka.ms/UnifiedEOMT` via the Exchange Management Shell. Permanent fixes are forthcoming for Exchange SE RTM (publicly available SU); for Exchange 2016 and Exchange 2019, the permanent update will be **distributed only to organisations enrolled in the Period 2 Exchange Server Extended Security Update programme**, which is a notable operational risk for any CH/EU public-sector organisation that has not enrolled. Detection: IIS access logs on the front-end Exchange role for `/owa/` URLs containing `<script>` fragments or HTML-encoded equivalents in query strings; Exchange Application Event Log EID 4 (`MSExchange Management`) for EEMS mitigation-state changes; EDR alerts on browser processes spawning unexpected children from OWA sessions. EEMS verification: `Get-ExchangeDiagnosticInfo -Server <name> -Process MSExchangeHMWorker -Component EemsMitigation -SettingName MitigationsApplied`.
