On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
A new security flaw affecting on-premise Exchange Server versions has been revealed by Microsoft, which claims it has been actively exploited in the wild.
The vulnerability has been identified as a spoofing fault resulting from a cross-site scripting flaw and is tagged as CVE-2026-42897 (CVSS score: 8.1). The problem was identified and reported by an unidentified researcher.
According to a Thursday advisory from the tech giant, improper neutralization of input during web page creation (often known as "cross-site scripting") in Microsoft Exchange Server enables an unauthorized attacker to perform spoofing over a network.
An attacker could weaponize the vulnerability by sending a user a crafted email that, when viewed in Outlook Web Access and subject to additional "certain interac...


