A Critical Microsoft Exchange Vulnerability Is Being Actively Exploited — Here’s What to Check
If your organization runs Microsoft Exchange Server on-premises, there’s a vulnerability you need to know about — not because it’s theoretical, but because Microsoft has confirmed it’s already being used in real attacks.
Here’s the plain version, what to check on your own environment, and what to do next.
What happened
On May 14, 2026, Microsoft disclosed CVE-2026-42897, a critical vulnerability (CVSS 8.1) in Outlook Web Access, the web-based interface for Exchange Server. The flaw is a cross-site scripting issue — the kind of bug where an attacker can sneak executable code into something a browser trusts.
In practice, it works like this: an attacker sends a specially crafted email. If the recipient opens it in Outlook Web Access, JavaScript embedded in the message can run in their browser session. No password needed, no prior access to your network — just one email, opened once.
Microsoft’s own advisory confirms this wasn’t caught in a lab. It was already being exploited before the public even knew it existed, and security researchers have tied active campaigns to a Russia-linked espionage group (tracked as Laundry Bear, also known as Void Blizzard) targeting government agencies and private-sector organizations across the US and Europe.
This matters for a straightforward reason: Exchange Server sits at the center of your organization’s identity and communication. A foothold there can mean stolen credentials, hijacked mailboxes, and a persistence mechanism that’s hard to fully clean up.
Who’s affected
This affects on-premises Exchange Server — specifically Exchange Server Subscription Edition, Exchange 2019 (CU14 and CU15), and Exchange 2016 (CU23). If your mail flows through Exchange Online only, this particular flaw doesn’t apply to you. If you’re running a hybrid environment with an on-prem Exchange server anywhere in the mix, it does.
One detail worth flagging directly: if anyone in your organization accesses Outlook Web Access using Internet Explorer, or Microsoft Edge in “IE mode,” Microsoft’s own mitigation doesn’t protect them — those browsers don’t support the security control the fix relies on. If that’s still in use anywhere in your environment, it’s worth eliminating regardless of this specific vulnerability.
What to check right now
Patching closes the door, but it doesn’t tell you whether someone already walked through it. If your Exchange server was exposed between mid-May and whenever you applied a fix, that’s your window to look at. A few concrete things worth checking:
Patch and mitigation status. Confirm which Exchange update level you’re actually running, and whether the July 2026 security update is installed — Microsoft recommends it specifically, since it also addresses a related vulnerability (CVE-2026-55008) and lets you remove any interim mitigations you had in place.
Browser exposure. Check whether OWA was ever accessed via Internet Explorer or Edge IE mode during the exposure window. If so, treat those sessions as unprotected regardless of when you patched.
Mailbox and message anomalies. Look for messages where the version stored on the server doesn’t match what a user remembers seeing — attackers using this flaw have been observed rewriting messages after the exploit runs, to erase the evidence.
Outlook add-ins and OAuth tokens. Review add-ins with mailbox read/write permissions, and look for OAuth tokens issued to add-ins you don’t recognize. This has been a persistence and credential-theft path in observed campaigns.
Authentication logs. Watch for unusual OWA login activity, mailbox rule changes nobody remembers making, or unexpected password resets — especially shortly after a user opened an unfamiliar email.
Outbound network activity. Unusual traffic to code-hosting or file-sharing platforms, or connections to unfamiliar destinations, is worth a closer look.
Final thought: Microsoft’s advisory doesn’t publish specific indicators of compromise for this one, and cross-site scripting attacks generally leave a thinner trail than most people expect. That’s exactly why the behavioral checks above matter more than searching for a single “smoking gun” signature — and why, if you find something that looks off, it’s worth having someone experienced take a second look before you conclude either way.
What to do next
If you haven’t already: patch. Install the July 2026 Exchange security update for your version, confirm the Exchange Emergency Mitigation Service is (or was) enabled, and get Internet Explorer / IE mode out of your OWA access path entirely.
If you have reason to believe you were exposed during the window before patching — or you’re just not sure — that’s a good moment for a second set of eyes. This is exactly the kind of situation where a quick, practical conversation is worth more than guessing.
If you want a second opinion on whether this affects you, or help checking your environment, talk to a founder directly — no sales process, no obligation.
Terry Bradley, CISSP, is the President and Founder of Mile High Cyber, with over 30 years of experience in cybersecurity. A CISSP since 2008, he specializes in penetration testing, vulnerability management, and virtual CISO services, helping small and mid-sized organizations identify, remediate, and verify their most critical security risks.