{"id":13541,"date":"2026-06-11T10:03:43","date_gmt":"2026-06-11T10:03:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/11\/microsoft-exchange-server-0-day-vulnerability-exploited-in-attacks-using-weaponized-email\/"},"modified":"2026-06-11T10:03:43","modified_gmt":"2026-06-11T10:03:43","slug":"microsoft-exchange-server-0-day-vulnerability-exploited-in-attacks-using-weaponized-email","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/11\/microsoft-exchange-server-0-day-vulnerability-exploited-in-attacks-using-weaponized-email\/","title":{"rendered":"Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks Using Weaponized Email"},"content":{"rendered":"<p>    Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks Using Weaponized Email<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Microsoft has confirmed active exploitation of a new<a href=\"https:\/\/cybersecuritynews.com\/microsoft-exchange-windows-11-and-cursor-zero-days-exploited-pwn2own\/\" target=\"_blank\" rel=\"noreferrer noopener\"> zero\u2011day spoofing flaw<\/a> in on\u2011premises Exchange Server, tracked as CVE\u20112026\u201142897.<\/p>\n<p class=\"wp-block-paragraph\">The flaw allows attackers to execute arbitrary JavaScript in <a href=\"https:\/\/cybersecuritynews.com\/microsoft-outlook-com-issue-blocks-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">Outlook Web Access (OWA)<\/a> simply by sending a weaponized email that a victim opens in a browser.<\/p>\n<p class=\"wp-block-paragraph\">On May 14, 2026, Microsoft disclosed CVE\u20112026\u201142897 as a spoofing vulnerability in Exchange Outlook Web Access that stems from improper neutralization of user input during web page generation, essentially a cross\u2011site scripting (XSS) bug (CWE\u201179).<\/p>\n<p class=\"wp-block-paragraph\">An unauthenticated attacker can send a specially crafted email. When the target opens it in OWA and specific interaction conditions are met, attacker\u2011supplied JavaScript executes in the browser context of the logged\u2011in user.<\/p>\n<p class=\"wp-block-paragraph\">The flaw affects all update levels of Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE), while <a href=\"https:\/\/cybersecuritynews.com\/microsoft-365-network-level-disruption\/\" target=\"_blank\" rel=\"noreferrer noopener\">Exchange Online (Microsoft 365)<\/a> is not impacted.<\/p>\n<h2 id=\"h-microsoft-exchange-server-0-day-vulnerability\" class=\"wp-block-heading\"><strong>Microsoft Exchange Server 0-Day Vulnerability<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Microsoft\u2019s exploitability assessment classifies the CVE as \u201c<a href=\"https:\/\/cybersecuritynews.com\/microsoft-exchange-and-windows-clfs-vulnerabilities-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">Exploitation Detected<\/a>,\u201d confirming that real\u2011world attacks are already leveraging this issue.<\/p>\n<p class=\"wp-block-paragraph\">CVE\u20112026\u201142897 is rated Critical with a CVSS v3.1 base score of 8.1, reflecting a network\u2011reachable attack that requires no privileges on the attacker side and only basic user interaction (opening an email in OWA).<\/p>\n<p class=\"wp-block-paragraph\">Successful exploitation allows the attacker to execute JavaScript in the victim\u2019s browser session, enabling email spoofing, <a href=\"https:\/\/cybersecuritynews.com\/stock-exchange-executives-outlook-account-targeted\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential theft<\/a>, session hijacking, and actions performed on behalf of the compromised user.<\/p>\n<p class=\"wp-block-paragraph\">Because the attack is delivered via email and triggers when content is rendered in OWA, it can bypass traditional attachment\u2011 or link\u2011focused security controls and blend into normal mailbox activity.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/techcommunity.microsoft.com\/blog\/exchange\/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897\/4518498\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft notes that exploitation <\/a>has only been observed via OWA rendering Exchange Online and non\u2011OWA access paths are currently not known to be affected.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft\u2019s primary short\u2011term defense is the Exchange Emergency Mitigation (EM) Service, which is enabled by default on supported on\u2011premises Exchange servers and automatically deploys mitigation M2.1.x for CVE\u20112026\u201142897.<\/p>\n<p class=\"wp-block-paragraph\">Organizations can verify mitigation status using the EM \u201cViewing Applied Mitigations\u201d guidance or the Exchange Health Checker script, which surfaces an EEMS check section in its HTML report.<\/p>\n<p class=\"wp-block-paragraph\">For disconnected or air\u2011gapped environments, Microsoft provides the Exchange On\u2011Premises Mitigation Tool (EOMT), which applies CVE\u2011specific mitigations per server via a PowerShell script named PowerShell.ps1 with the CVE parameter.<\/p>\n<p class=\"wp-block-paragraph\">These mitigations rely on browser<a href=\"https:\/\/cybersecuritynews.com\/content-security-policy-bypass\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Content Security Policy<\/a> and therefore do not protect users accessing OWA through Internet Explorer or Edge in Internet Explorer Mode, which lacks CSP support.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/cybersecuritynews.com\/microsoft-patch-tuesday-june-2026\/\" target=\"_blank\" rel=\"noreferrer noopener\">On June 9, 2026, Microsoft released Security Updates<\/a> (SUs) for Exchange SE RTM, Exchange Server 2019 CU14\/CU15, and Exchange Server 2016 CU23 that include a permanent fix for CVE\u20112026\u201142897, with the 2016\/2019 updates available only to customers in the Period 2 Extended Security Update (ESU) program.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft recommends installing the June 2026 SUs as soon as possible and keeping the <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-42897\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE\u20112026\u201142897 mitigation<\/a> in place as an extra defense layer even after patching.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft warns that applying the mitigation (via EM Service or EOMT) may break or degrade certain OWA features, including calendar printing, inline image display in the reading pane, OWA Light, published calendars, and the OWACalendar proxy health set, which may trigger false alerts in monitoring systems.<\/p>\n<p class=\"wp-block-paragraph\">These issues are expected to clear once organizations install the June 2026 update and then manually remove the mitigation if they choose to do so.<\/p>\n<p class=\"wp-block-paragraph\">The June 2026 blog also highlights that EM and feature flighting services will stop consuming new configuration files from July 2026 unless Exchange servers are updated to at least the June 2026 level, reinforcing the need to move to current builds.<\/p>\n<p class=\"wp-block-paragraph\">For organizations still on Exchange 2016\/2019 without Period 2 ESU, Microsoft advises migrating to Exchange SE to maintain access to future security fixes.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsoft-exchange-server-0-day-exploited\/\">Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks Using Weaponized Email<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsoft-exchange-server-0-day-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks Using Weaponized Email Microsoft has confirmed active exploitation of a new zero\u2011day spoofing flaw in on\u2011premises Exchange Server, tracked as CVE\u20112026\u201142897. The flaw allows attackers to execute arbitrary JavaScript in Outlook Web Access (OWA) simply by sending a weaponized email that a victim opens in a browser. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-13541","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13541"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13541"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13541\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}