CISA adds actively exploited Microsoft Exchange Server XSS flaw CVE-2026-42897 to KEV catalog

CISA on May 15, 2026 added CVE-2026-42897, a Microsoft Exchange Server cross-site scripting vulnerability, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Under BOD 22-01, federal civilian agencies must remediate by CISA's due date, and CISA urged all organizations to prioritize patching KEV-listed flaws.
Why it matters: Active exploitation of an Exchange Server flaw raises immediate risk for organizations running the product, especially federal agencies subject to KEV deadlines. Defenders should identify exposed Exchange instances and prioritize remediation or mitigation quickly.

Sources

Microsoft Patch Tuesday Security Recap: June 2026 Edition
Arctic Wolf Labs 2026.06.11 63% relevant
The article notes that CVE-2026-42897 was the actively exploited zero-day in this Patch Tuesday cycle and reiterates Microsoft's Exchange Emergency Mitigation Service guidance, connecting this patch release to the previously tracked active exploitation.
Microsoft Patches Exploited Exchange Server Vulnerability
Eduard Kovacs 2026.06.11 95% relevant
This article updates the same underlying event by adding that Microsoft has now released patches for the previously mitigations-only zero-day CVE-2026-42897 affecting Exchange Server Subscription Edition, 2016, and 2019.
Microsoft patches Exchange Server zero-day exploited in attacks
Sergiu Gatlan 2026.06.10 96% relevant
This article is a direct update to the same CVE-2026-42897 event, adding that Microsoft has now released June 2026 security updates to patch the actively exploited Exchange Server flaw after earlier warning of exploitation and temporary mitigations.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA 2026.05.15 100% relevant
This article is the first tracked item here establishing the specific KEV event for CVE-2026-42897 and its active exploitation status.
← Back to all stories