TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Service news

Exchange Vulnerability Turns OWA Into Script-Launching Tool

Akinola Ajibola by Akinola Ajibola
May 15, 2026
in Service news
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • A vulnerability in on-premises Exchange Server that could cause victims’ browsers to execute unexpected scripts has been discovered by Microsoft.
  • The vulnerability, known as CVE-2026-42897, which has been tracked, impacts Outlook Web Access (OWA) and can be activated via a specifically constructed email that is opened...
  • The vulnerability in Outlook Web Access (OWA) allows unauthorized malicious payloads to execute in user mailboxes.

A vulnerability in on-premises Exchange Server that could cause victims’ browsers to execute unexpected scripts has been discovered by Microsoft.

The vulnerability, known as CVE-2026-42897, which has been tracked, impacts Outlook Web Access (OWA) and can be activated via a specifically constructed email that is opened in OWA, provided that “certain interaction conditions are met.” Attackers can execute JavaScript arbitrarily within the browser context of the mark as a reward.

The vulnerability in Outlook Web Access (OWA) allows unauthorized malicious payloads to execute in user mailboxes.

Administrators will be alarmed by the advisory’s description of the problem as a spoofing vulnerability resulting from cross-site scripting, which seems to be being exploited. The bug received an 8.1 CVSS score. 

Regardless of their degree or level of upgrade, Exchange Server 2016, 2019, and the most recent version, Exchange Server Subscription Edition (SE), are all impacted. The Exchange Emergency Mitigation (EM) Service has made a mitigation available.

Microsoft had cautioned that the mitigation might cause other issues, such as the OWA Print Calendar feature not working (alternatively, Microsoft advises the use of a screenshot or the Outlook desktop client instead) and inline graphics ceasing to operate in the recipient’s OWA reading pane (alternatively, Microsoft advises the use of attachments).

Also worth reading
Microsoft Cloud Growth Jumps As Azure Gives AI Spending A Better Answer Microsoft Launches MAI-Cyber-1-Flash As AI Security Becomes A Model Race Microsoft And Mistral Sign Multibillion-Dollar European AI Deal AMD Lands Microsoft As Helios AI Rack Customer In Nvidia Challenge Critical Vulnerability In Microsoft Authenticator Exposes Users To Token Theft Microsoft Is Becoming an AI Company and Xbox Is Paying the Price

Lastly, OWA Light may not function correctly. And the affected users should think about upgrading, as Microsoft deprecated this in the 2024 edition.

In a situation(s) when clients are not utilizing the EM service, the mitigation can also be manually implemented. These might be in air-gapped or disconnected environments, which are precisely the kinds of settings where on-premises Exchange tends to exist.

Although only the Exchange SE version will be made accessible to the general public, Microsoft is working on a complete security update. It will only be available to Exchange 2016 and 2019 when users are signed up for Period 2 of the Exchange Server Extended Security Updates (ESU) program. This month marked the start of the second Exchange Server ESU period, and Microsoft issued a strong warning that there would be no further extensions to users. Exchange Online is not impacted by the issue.

Microsoft has not disclosed any information regarding the exploit’s functionality or the extent to which it is being used. 

While Microsoft prepares a permanent security update, administrators should verify that automated mitigations are active via the Exchange Emergency Mitigation Service using the Health Checker script or deploy the standalone EOMT tool on offline networks, but note that these measures may temporarily disrupt inline image rendering and calendar printing in OWA.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • microsoft-authenticator_fhch
    Critical Vulnerability In Microsoft Authenticator…
  • 1_8_VsolmlGbZ-OhZN0wEgrw
    Over 46,000 Grafana Instances Vulnerable to Account Takeover
  • 020tYFWBL4Yz8jIIFUdKDR1-22
    A Fix to Microsoft Windows Defender And Security Flaws
  • was-ist-cpanel
    Hackers Are Exploiting Critical cPanel Bug, Putting…
  • Microsoft Teams
    Microsoft Teams Vulnerability Exposes User Systems
  • Exchange_1500x1500 (1)
    Microsoft to Retire Exchange Web Services in 2027
  • Google-Chrome-headpic
    Google Patches Fourth Chrome Zero-Day of 2026 as…
  • shutterstock_chatgpt
    Researchers Warn ChatGPT Crawler May Cause DDoS…
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Service news
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: ExchangeExchange Servermicrosoftvulnerability
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Google Lets Users Remove Visible AI Watermarks, But The Trust Question Remains August 14, 2026
  • Airtel Africa And Starlink Take Satellite-To-Mobile Connectivity To DR Congo August 14, 2026
  • Writer’s Palmyra X6 Tackles The Enterprise AI Cost Problem August 14, 2026
  • Uber And Pony.ai Want 2,000 Robotaxis Across Europe August 14, 2026
  • Z.ai’s GLM-5.3 Shows China’s Open-Weight Coding Race Is Speeding Up August 14, 2026
  • Google Makes Gemini 3.7 Flash Cheaper For Coding And Agents August 14, 2026
  • Opinion: Africa Cannot Let Foreign AI Models Decide What Is Too Political August 14, 2026
  • Why The Zenith Bank Data Incident Looks More Like An AI-Era Hack August 14, 2026
  • Microsoft Word Copilot Adds Anthropic Models Beside OpenAI August 13, 2026
  • Microsoft’s Copilot Cleanup Shows AI Super Apps Still Need Focus August 13, 2026
  • Taiwan Confirms AI Agents Are Now Part Of Real Cyberattacks August 13, 2026
  • Twitch Will Train Amazon AI On Streamers’ Content By Default August 13, 2026

Browse Archives

August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.