Microsoft has disclosed an actively exploited zero-day in on-premises Exchange Server that affects Outlook on the web, also known as OWA. The flaw, tracked as CVE-2026-42897, can let an attacker send a specially crafted email that triggers malicious JavaScript when opened under certain conditions.
Microsoft said the issue affects Exchange Server 2016, Exchange Server 2019 and Exchange Server Subscription Edition, while Exchange Online is not impacted. The vulnerability is described as a cross-site scripting issue tied to improper neutralization of input during web page generation.
No permanent patch is available yet. Microsoft is telling administrators to rely on the Exchange Emergency Mitigation Service, which can automatically apply a temporary mitigation, and on the Exchange On-premises Mitigation Tool for disconnected or air-gapped environments.
The company’s guidance comes as on-premises Exchange remains a frequent target for attackers. Microsoft’s Exchange team has urged administrators to verify that the mitigation has been applied using the Exchange Health Checker script.
Microsoft also said the eventual Exchange SE fix will be released as a public security update, while Exchange 2016 and 2019 updates will be limited to customers enrolled in the Period 2 Extended Security Update program.
Read Article: India and UAE Announce $5 Billion Investments Alongside New Energy and Defence Deals

