Knox CVE Database
/
CVE-2026-42897
Medium
6.1

CVE-2026-42897: Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

Added to the CISA KEV catalog:
May 15, 2026

Overview

Microsoft Exchange Server's Outlook Web Access (OWA) interface fails to sanitize attacker-supplied input before rendering it in generated web pages. An unauthenticated attacker who can deliver a crafted link or message to an OWA user can cause arbitrary JavaScript to execute in that user's browser, enabling session token theft, credential harvesting, or UI spoofing against the authenticated victim. Exchange Server 2016 and 2019 across multiple cumulative update tracks are affected.

Vulnerability details

Affected vendor
Microsoft
Affected product
Exchange Server
Weakness type (CWE)
CWE-79

This is a CWE-79 cross-site scripting flaw in OWA's web page generation pipeline. When user-supplied input is incorporated into a dynamically generated page without proper neutralization, the browser treats that input as executable script rather than inert content. In Exchange's case, the trust boundary between attacker-controlled data and the OWA rendering layer is not enforced, so malicious HTML or JavaScript injected into a request or message survives into the page the victim's browser loads and parses.


An unauthenticated attacker crafts a payload, either a malicious URL or a message delivered to an OWA user, containing JavaScript that OWA reflects or stores and later renders. When the victim interacts with that content, the script executes inside the victim's authenticated browser session. From that position the attacker can steal session tokens, capture credentials entered into spoofed UI elements, or issue requests to OWA on the victim's behalf. Exploitation requires the victim to take an action such as clicking a link or opening a message, but the attacker needs no credentials of their own.

Severity and impact

6.1
Medium
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality impact
Low
Integrity impact
Low
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor network egress and proxy logs for outbound connections from OWA users' browsers to unexpected external hosts immediately following OWA page loads; this pattern, absent in normal OWA use, may indicate JavaScript-driven session token exfiltration.
  • Inspect web application firewall or reverse-proxy logs for OWA requests containing encoded script tags, event handler attributes, or JavaScript URI schemes in query parameters or message body fields, which are not present in legitimate OWA traffic.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
May 29, 2026

Additional hardening

  • Upgrade Exchange Server 2016 CU23 to build 15.01.2507.069 or later, Exchange Server 2019 CU14 to 15.02.1544.041 or later, CU15 to 15.02.1748.046 or later, and Exchange Server SE to 15.02.2562.043 or later. See References for the full vendor advisory.
  • Restrict OWA access to known corporate IP ranges or require VPN authentication before reaching the OWA endpoint, reducing the attacker's ability to deliver crafted payloads to internal users.
  • Deploy a web application firewall in front of OWA configured to inspect and block requests containing script injection patterns in URL parameters and POST bodies.
  • Enable Microsoft's Exchange Emergency Mitigation Service, which can apply interim XML-based mitigations automatically while a full patch deployment is completed.

Key dates

Published (NVD)
May 14, 2026
Added to CISA KEV
May 15, 2026
Remediation deadline
May 29, 2026
Last updated
June 17, 2026

References

Frequently asked questions

Does CVE-2026-42897 affect my FedRAMP authorization?

If Microsoft Exchange Server runs inside your authorization boundary, yes. CVE-2026-42897 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, and the May 29, 2026 remediation deadline has already passed. For a FedRAMP-authorized service, an unpatched KEV in your boundary is an assessor finding. An overdue one is a finding your assessor and sponsoring agency can see right now. Your options are to remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-42897?

Knox does not patch your Microsoft Exchange Server software. Under the FedRAMP shared-responsibility model, remediating CVE-2026-42897 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage that document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you have to handle on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a CVE like CVE-2026-42897, that means exposure surfaces during continuous monitoring rather than only when an assessor flags it at review time, giving you more time to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-42897's remediation deadline of May 29, 2026 has passed. What happens now?

An unremediated CVE-2026-42897 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out and documenting why the deadline was missed is what keeps your authorization clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.