CVE-2026-42897 – Microsoft Exchange Server 2016 Cumulative Update 23

CVSS 8.1 IMPORTANT Zero Day – Immediate Deployment

“A single malicious email can become an entry point when systems remain unpatched.”

This patch addresses CVE-2026-42897, a cross-site scripting (CWE-79) vulnerability affecting Microsoft Exchange Server 2016 Cumulative Update 23. The CVSS score is 8.1, which is High severity. Verified active exploitation has been reported, making prompt deployment of the security update a priority. The vulnerability is not identified as Remote Code Execution (RCE) or Elevation of Privilege (EoP).

An attacker can exploit this vulnerability by sending a specially crafted email to a user. If the email is opened in Outlook Web Access (OWA) and the required user interaction occurs, arbitrary JavaScript can execute within the user’s browser session. Microsoft recommends installing the July 2026 Exchange Server Security Updates as soon as possible to protect against this vulnerability and the related CVE-2026-55008. Until the update is installed, the Exchange Emergency Mitigation Service (EEMS) provides automatic mitigation when enabled. After applying the July 2026 security updates, temporary mitigations deployed through EEMS or the EOMT script can be removed. Microsoft also advises against using Internet Explorer or Microsoft Edge in Internet Explorer Mode to access Outlook Web Access because those browsers do not support the required Content Security Policy (CSP) protections.

Key Details

Affected Product
Microsoft Exchange Server
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-79
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.