🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Microsoft Exchange Server Outlook Web Access XSS (CVE-2026-42897) | MSSP Advisory
High🔴 KEV ALERTConfirmed
DateMay 15, 2026
CVECVE-2026-42897
CVSS Score8.1
Affectedexchange_server
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CISA added CVE-2026-42897 to the Known Exploited Vulnerabilities catalog targeting Microsoft Exchange Server's Outlook Web Access with a cross-site scripting flaw that allows arbitrary JavaScript execution. The vulnerability is actively exploited in the wild and carries a May 2026 remediation deadline for federal agencies.
⚠️Why It Matters for MSSPs
Your Exchange infrastructure faces direct compromise through client-side attacks that can steal credentials and pivot into your management tools. Every client running Exchange Server creates an advisory obligation since this XSS vulnerability can serve as the entry point for broader network compromise campaigns.
✅Recommended Action
Audit all client Exchange deployments within 24 hours and prioritize patching based on external exposure and privilege levels. Contact Microsoft immediately for mitigation guidance and prepare contingency plans for clients who cannot patch quickly enough to meet security requirements.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.