Exchange Server zero-day exploitation for email delivery
Key Questions
What vulnerabilities are being actively exploited in Exchange Server?
The exploitation involves CVE-2026-42897, an XSS flaw in Outlook Web App (OWA) triggered by a single crafted email with no attachments or spoofing, along with CVE-2026-6973 enabling remote code execution. These zero-days target on-premises Exchange deployments.
What mitigation steps and deadlines have been issued for these Exchange vulnerabilities?
An emergency mitigation was released on May 14, and the issues are listed in CISA's Known Exploited Vulnerabilities catalog with a federal patch deadline of May 29. No official patch is available yet, though the advisory outlines technical details and recommended actions.
Which organizations face heightened risks from this Exchange exploitation?
On-premises finance organizations are at elevated risk of post-phish escalation. The advisory also notes mentions of APT37 deepfakes and OWA CVEs in strategic briefings, along with a recommendation to disable SVG in Outlook.
Active exploitation of CVE-2026-42897 (XSS in OWA triggered by single crafted email, no attachments, spoofing) and CVE-2026-6973 RCE. Emergency mitigation May 14, CISA KEV, federal patch deadline May 29. Post-phish escalation risk for on-prem finance orgs; Outlook SVG disable noted. APT37 deepfake and OWA CVE mentions in strategic briefings. Advisory provides technical details, risks, and mitigations (no patch yet). New SVG phishing evasion technique using obsolete MIME type adds to evasion landscape. A recent video walkthrough (2026-06-24) further details the XSS-to-session-hijack chain.