Titre test Alerte
Published on : September 10, 2026extrait test
Read moreOn May 14, 2026, Microsoft disclosed CVE-2026-42897, a vulnerability affecting on-premises Microsoft Exchange Server. The vulnerability can allow an unauthenticated attacker to perform an indirect remote code injection (XSS) and bypass security policies when a user opens a specially crafted email through Outlook Web Access (OWA).
Microsoft reported that the vulnerability was actively exploited. The vulnerability has also been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.
Impacts identified
Successful exploitation may allow an attacker to execute arbitrary JavaScript in the user’s browser context and bypass certain security controls.
For microfinance institutions, a compromised Exchange environment could expose sensitive communications and increase the risk of unauthorized access to corporate information and accounts.
Affected systems
The vulnerability affects on-premises:
Exchange Online is not affected.
Recommended actions