Vulnerability in Microsoft Exchange Server – Microfinance-CERT
HIGH

Vulnerability in Microsoft Exchange Server

On May 14, 2026, Microsoft disclosed CVE-2026-42897, a vulnerability affecting on-premises Microsoft Exchange Server. The vulnerability can allow an unauthenticated attacker to perform an indirect remote code injection (XSS) and bypass security policies when a user opens a specially crafted email through Outlook Web Access (OWA).

Microsoft reported that the vulnerability was actively exploited. The vulnerability has also been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.

 

Impacts identified

Successful exploitation may allow an attacker to execute arbitrary JavaScript in the user’s browser context and bypass certain security controls.

For microfinance institutions, a compromised Exchange environment could expose sensitive communications and increase the risk of unauthorized access to corporate information and accounts.

 

Affected systems

The vulnerability affects on-premises:

  • Microsoft Exchange Server 2016 – Cumulative Update 23
  • Microsoft Exchange Server 2019 – Cumulative Update 14
  • Microsoft Exchange Server 2019 – Cumulative Update 15
  • Microsoft Exchange Server Subscription Edition – RTM

Exchange Online is not affected.

 

Recommended actions

  • Apply the latest available Microsoft Exchange Server security updates for the affected environment.
  • Verify that the installed Exchange build is no longer within the vulnerable range.
  • Ensure that Exchange Emergency Mitigation (EOM) is active where the security update cannot yet be applied.
  • Review Exchange and OWA logs for signs of suspicious activity, particularly where exploitation may have occurred.
  • For Exchange Server 2016 and 2019, verify eligibility for the Period 2 Extended Security Update (ESU) program, as the 2026 security updates require enrollment in this progra

  • Reference TG-IMF-2026-014
  • Date and time July 29, 2026 - 13:27
  • Date of last update September 2, 2026 - 11:56
  • Category Alerts
  • TLP classification TLP:CLEAR
  • Security Level HIGH