🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Microsoft Exchange OWA XSS Zero-Day Active (CVE-2026-42897) | MSSP Advisory
Critical🔴 KEV ALERTConfirmed
DateMay 18, 2026
CVECVE-2026-42897
CVSS Score8.1
Affectedexchange_server
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CVE-2026-42897 is a cross-site scripting vulnerability in Microsoft Exchange that allows attackers to compromise Outlook Web Access mailboxes. The zero-day is currently being exploited in the wild with no patch available from Microsoft. Attackers can execute malicious scripts when users access OWA, potentially stealing credentials and session tokens.
⚠️Why It Matters for MSSPs
Your own email infrastructure is directly exposed if you run Exchange on-premises for internal operations or client services. Every client running Exchange Server with OWA exposed faces immediate mailbox compromise risk, and you need to advise them on emergency mitigations before they get breached through their primary business communication channel.
✅Recommended Action
Disable Outlook Web Access on all Exchange servers immediately until Microsoft releases a patch, then notify clients within 24 hours with specific instructions to do the same.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.