Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
Microsoft Exchange Server's Outlook Web Access (OWA) interface fails to sanitize attacker-supplied input before rendering it in generated web pages. An unauthenticated attacker who can deliver a crafted link or message to an OWA user can cause arbitrary JavaScript to execute in that user's browser, enabling session token theft, credential harvesting, or UI spoofing against the authenticated victim. Exchange Server 2016 and 2019 across multiple cumulative update tracks are affected.
This is a CWE-79 cross-site scripting flaw in OWA's web page generation pipeline. When user-supplied input is incorporated into a dynamically generated page without proper neutralization, the browser treats that input as executable script rather than inert content. In Exchange's case, the trust boundary between attacker-controlled data and the OWA rendering layer is not enforced, so malicious HTML or JavaScript injected into a request or message survives into the page the victim's browser loads and parses.
An unauthenticated attacker crafts a payload, either a malicious URL or a message delivered to an OWA user, containing JavaScript that OWA reflects or stores and later renders. When the victim interacts with that content, the script executes inside the victim's authenticated browser session. From that position the attacker can steal session tokens, capture credentials entered into spoofed UI elements, or issue requests to OWA on the victim's behalf. Exploitation requires the victim to take an action such as clicking a link or opening a message, but the attacker needs no credentials of their own.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Microsoft Exchange Server runs inside your authorization boundary, yes. CVE-2026-42897 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, and the May 29, 2026 remediation deadline has already passed. For a FedRAMP-authorized service, an unpatched KEV in your boundary is an assessor finding. An overdue one is a finding your assessor and sponsoring agency can see right now. Your options are to remediate it or formally document the mitigation and the delay.
Knox does not patch your Microsoft Exchange Server software. Under the FedRAMP shared-responsibility model, remediating CVE-2026-42897 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage that document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you have to handle on your own.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a CVE like CVE-2026-42897, that means exposure surfaces during continuous monitoring rather than only when an assessor flags it at review time, giving you more time to act.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
An unremediated CVE-2026-42897 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out and documenting why the deadline was missed is what keeps your authorization clean and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)








