Microsoft disclosed that an on-premises Microsoft Exchange Server security vulnerability, CVE-2026-42897 (CVSS score 8.1), is being exploited “in the wild.” The flaw is described as a cross-site scripting (XSS) issue that can lead to spoofing behavior over a network. Microsoft credits an anonymous researcher with discovering and reporting the problem.
According to the reporting, CVE-2026-42897 affects specific Exchange Server on-premises versions, including Exchange Server 2019 and 2016, as well as Subscription Edition RTM. Exchange Online is reported as not affected.
Microsoft states that a permanent fix is not yet available. In the interim, Microsoft has issued temporary mitigations to reduce risk while remediation is prepared. The reports characterize the activity as unauthorized attackers taking advantage of the unpatched vulnerability to spoof users or messages through the Exchange environment.