DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-42897PUBLISHED: 2026-05-14
HIGHCVE-2026-42897

Microsoft Exchange Server OWA XSS Spoofing Zero-Day (Unpatched)

VENDOR: Microsoft//PRODUCT: Exchange Server 2016, 2019, Subscription Edition
8.1
HIGH
CVSS 3.1
NO PATCH AVAILABLE
This vulnerability has no vendor patch at this time. Apply mitigation steps below or restrict network access to affected systems.
PATCH STATUS
NO PATCH
EXPLOIT STATUS
LIMITED EXPLOITATION

An improper input neutralization (XSS) flaw in Outlook Web Access (OWA) allows an unauthenticated attacker to send a specially crafted email that executes arbitrary JavaScript in the victim's browser when opened in OWA, enabling session hijacking and spoofing attacks. Microsoft confirmed active exploitation in the wild as of May 14, 2026, and has released temporary mitigations via the Exchange Emergency Mitigation Service (auto-applied as M2.1.x) while a permanent patch is developed. No patch is yet available; Exchange Online users are unaffected.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
REQUIRED
Scope / Impact
UNCHANGED
C:H · I:H · A:N
AFFECTED VERSIONSExchange Server 2016, Exchange Server 2019, Exchange Server Subscription Edition (all CU levels); Exchange Online is NOT affected
  • https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498
  • https://securityaffairs.com/192204/security/cve-2026-42897-microsoft-confirms-active-exploitation-of-exchange-server-zero-day.html
  • https://www.helpnetsecurity.com/2026/05/15/exchange-server-cve-2026-42897-exploited/
  • https://www.securityweek.com/microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn