Microsoft Exchange Server OWA XSS Active Exploitation | MSSP Advisory

Critical
DateMay 15, 2026
📋Executive Summary
Microsoft disclosed a zero-day cross-site scripting vulnerability in Exchange Server with CVSS 8.1 that affects Outlook Web Access and is actively exploited in the wild. The XSS flaw allows attackers to execute malicious code in the context of the victim's OWA session. Microsoft has not released a patch yet but confirms active exploitation is occurring.
⚠️Why It Matters for MSSPs
Your clients running on-premises Exchange servers are exposed to session hijacking and credential theft through their webmail interface right now. Every MSSP managing Exchange environments carries immediate liability if breaches occur through this known exploited vulnerability while you stay silent.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.