---
schema: 1
kind: vulnerability
title: Exchange CVE-2026-42897 — Pwn2Own DEVCORE three-bug SYSTEM RCE chain emerges alongside active OWA-XSS exploitation
headline: Exchange CVE-2026-42897 — Pwn2Own DEVCORE three-bug SYSTEM RCE chain emerges alongside active OWA-XSS exploitation
summary: "UPDATE (originally covered 2026-05-15 and 2026-05-16 deep dive): DEVCORE's Orange Tsai chained three undisclosed Exchange Server bugs on Pwn2Own Berlin 2026 Day 2 to achieve unauthenticated remote code execution at SYSTEM privilege level, earning $200,000 (Zero Day Initiative, 2026-05-15; BleepingComputer …"
discovered_at: "2026-05-17T05:00:05Z"
event_date: 2026-05-15
run_id: 2026-05-17-4381863a
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - rce
  - zero-day
  - cisa-kev
  - no-patch
regions:
  - global
  - europe
  - switzerland
sectors:
  - public-sector
  - healthcare
  - education
entities: []
cves:
  - id: CVE-2026-42897
    cvss: "8.1"
    epss: null
    type: rce
    vector: user-interaction
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - mitigation-only
sources:
  - url: "https://www.zerodayinitiative.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results"
    publisher: "Zero Day Initiative, 2026-05-15"
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/pwn2own-day-two-hackers-demo-microsoft-exchange-windows-11-red-had-enterprise-linux-zero-days/"
    publisher: "BleepingComputer, 2026-05-15"
    role: corroborating
  - url: "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897"
    publisher: MSRC CVE-2026-42897
    role: corroborating
closed_sources: []
evidence:
  - quote: "UPDATE (originally covered 2026-05-15 and 2026-05-16 deep dive): DEVCORE's Orange Tsai chained three undisclosed Exchange Server bugs on Pwn2Own Berlin 2026 Day 2 to achieve unauthenticated remote code execution at SYSTEM privilege level, earning $200,000 (Zero Day Initiative, 2026-05-15 …"
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field); migration: update target unresolved (originally covered 2026-05-15)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Treat on-premises Microsoft Exchange as severely threatened through August Patch Tuesday 2026.** Verify EEMS service is enabled and mitigation M2.1.x is in the applied list (`Get-ExchangeDiagnosticInfo`); restrict ECP / EWS / OWA reachability from the internet at WAF or reverse proxy where business-feasible; accelerate any in-progress Exchange Online migration. The compound risk (CVE-2026-42897 active XSS, no permanent patch + DEVCORE Pwn2Own SYSTEM RCE chain under 90-day embargo) does not have a single mitigation. Reference: § 4 UPDATE on Exchange."
migrated_from: briefs/2026-05-17.md
---

**UPDATE (originally covered 2026-05-15 and 2026-05-16 deep dive):** DEVCORE's Orange Tsai chained three undisclosed Exchange Server bugs on Pwn2Own Berlin 2026 Day 2 to achieve unauthenticated remote code execution at SYSTEM privilege level, earning $200,000 ([Zero Day Initiative, 2026-05-15](https://www.zerodayinitiative.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results); [BleepingComputer, 2026-05-15](https://www.bleepingcomputer.com/news/security/pwn2own-day-two-hackers-demo-microsoft-exchange-windows-11-red-had-enterprise-linux-zero-days/)). This chain is separate from the actively-exploited CVE-2026-42897 (OWA stored XSS, no permanent patch; EEMS mitigation M2.1.x only) that the 2026-05-16 deep dive covered. ZDI verbatim: *"Orange Tsai (DEVCORE Research Team) earned $200,000 after chaining three bugs to gain remote code execution with SYSTEM privileges on Microsoft Exchange."*

The three bugs are under a 90-day Pwn2Own embargo — Microsoft must patch by approximately 2026-08-14 before ZDI publishes technical detail. Operationally, the compound risk for on-premises Exchange has materially worsened in 48 h: one actively exploited XSS without a permanent patch (M2 mitigation only, with known OWA Calendar Print / inline-image side-effects), plus a fresh unauthenticated SYSTEM RCE class that defenders cannot pre-emptively patch. CVE-2026-42897 remains in [CISA KEV (added 2026-05-15)](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) with EEMS as the only listed mitigation; the Microsoft Exchange blog post `addressing-exchange-server-may-2026-vulnerability-cve-2026-42897` linked from the MSRC advisory returns 502 on direct fetch and the MSRC entry itself is the operational primary ([MSRC CVE-2026-42897](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897)).

Defender response shift for on-premises Exchange 2016/2019/SE: treat the platform as severely threatened. Verify EEMS service is enabled (`Get-ExchangeDiagnosticInfo`, mitigation M2.1.x present in applied list); restrict ECP/EWS/OWA reachability from the internet at the WAF or reverse proxy where business-feasible; accelerate any in-progress Exchange Online migration; assume hypothetical compromise paths through both OWA-browser-context attacks (CVE-2026-42897) and a direct service-account SYSTEM RCE chain (Pwn2Own DEVCORE) until Microsoft ships permanent fixes for both. Exchange Online tenants are not in scope for either.
