TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Service news

Exchange Vulnerability Turns OWA Into Script-Launching Tool

Akinola Ajibola by Akinola Ajibola
May 15, 2026
in Service news
Share on FacebookShare on Twitter

A vulnerability in on-premises Exchange Server that could cause victims’ browsers to execute unexpected scripts has been discovered by Microsoft.

The vulnerability, known as CVE-2026-42897, which has been tracked, impacts Outlook Web Access (OWA) and can be activated via a specifically constructed email that is opened in OWA, provided that “certain interaction conditions are met.” Attackers can execute JavaScript arbitrarily within the browser context of the mark as a reward.

The vulnerability in Outlook Web Access (OWA) allows unauthorized malicious payloads to execute in user mailboxes.

Administrators will be alarmed by the advisory’s description of the problem as a spoofing vulnerability resulting from cross-site scripting, which seems to be being exploited. The bug received an 8.1 CVSS score. 

Regardless of their degree or level of upgrade, Exchange Server 2016, 2019, and the most recent version, Exchange Server Subscription Edition (SE), are all impacted. The Exchange Emergency Mitigation (EM) Service has made a mitigation available.

Microsoft had cautioned that the mitigation might cause other issues, such as the OWA Print Calendar feature not working (alternatively, Microsoft advises the use of a screenshot or the Outlook desktop client instead) and inline graphics ceasing to operate in the recipient’s OWA reading pane (alternatively, Microsoft advises the use of attachments).

Lastly, OWA Light may not function correctly. And the affected users should think about upgrading, as Microsoft deprecated this in the 2024 edition.

In a situation(s) when clients are not utilizing the EM service, the mitigation can also be manually implemented. These might be in air-gapped or disconnected environments, which are precisely the kinds of settings where on-premises Exchange tends to exist.

Although only the Exchange SE version will be made accessible to the general public, Microsoft is working on a complete security update. It will only be available to Exchange 2016 and 2019 when users are signed up for Period 2 of the Exchange Server Extended Security Updates (ESU) program. This month marked the start of the second Exchange Server ESU period, and Microsoft issued a strong warning that there would be no further extensions to users. Exchange Online is not impacted by the issue.

Microsoft has not disclosed any information regarding the exploit’s functionality or the extent to which it is being used. 

While Microsoft prepares a permanent security update, administrators should verify that automated mitigations are active via the Exchange Emergency Mitigation Service using the Health Checker script or deploy the standalone EOMT tool on offline networks, but note that these measures may temporarily disrupt inline image rendering and calendar printing in OWA.

Related Posts:

  • microsoft-authenticator_fhch
    Critical Vulnerability In Microsoft Authenticator…
  • 1_8_VsolmlGbZ-OhZN0wEgrw
    Over 46,000 Grafana Instances Vulnerable to Account Takeover
  • 020tYFWBL4Yz8jIIFUdKDR1-22
    A Fix to Microsoft Windows Defender And Security Flaws
  • was-ist-cpanel
    Hackers Are Exploiting Critical cPanel Bug, Putting…
  • Microsoft Teams
    Microsoft Teams Vulnerability Exposes User Systems
  • Google-Chrome-headpic
    Google Patches Fourth Chrome Zero-Day of 2026 as…
  • Cloudflare-AI_Bot-Blocking
    Cloudflare Blames React2Shell Protections for Outage
  • shutterstock_chatgpt
    Researchers Warn ChatGPT Crawler May Cause DDoS…

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: ExchangeExchange Servermicrosoftvulnerability
Akinola Ajibola

Akinola Ajibola

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Apple Adds Streaming-Style Subscription Packages To The App Store June 9, 2026
  • Apple Rolls Out Tailored App Store Recommendations June 9, 2026
  • Instagram Rolls Out Custom Profile Grid Arrangement Feature June 9, 2026
  • Signal Argues UK’s Device-Scanning Plan For Nude Images Threatens User Security June 9, 2026
  • UK Regulator Tells Social Media Firms To Stop Viral Illegal Content June 9, 2026
  • Apple Intelligence Gets Major AI Upgrade With New Siri, Safari Tools and Gemini-Powered Models June 9, 2026
  • Gogs Fixes Critical Zero-Day Bug That Enabled Remote Code Execution June 8, 2026
  • Amazon Adds AI-Powered Custom Merch Design June 8, 2026
  • NDPC & Meta Roll Out 2-Year Data Protection Program June 8, 2026
  • FCCPC Deregulates Airtime Lending in Nigeria June 6, 2026
  • Interswitch Jumps Into Africa’s Banking Tech Race With Temenos Deal June 6, 2026
  • Record Labels Face Lawsuit From Musicians’ Union Over AI Licensing June 6, 2026

Browse Archives

June 2026
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« May    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.