Microsoft Exchange Server Spoofing Flaw Actively Exploited, CVE-2026-42897
Microsoft has disclosed active exploitation of CVE-2026-42897, a spoofing flaw in on-premise Exchange Server. An emergency mitigation is available; a permanent patch is pending. On-premise deployments are at risk now.

Microsoft Exchange Server CVE-2026-42897 actively exploited 2026
Microsoft has confirmed that a vulnerability in on-premise Exchange Server is being actively exploited in the wild, making it one of the most urgent patching priorities for enterprise security teams this week.
The flaw, tracked as CVE-2026-42897 with a CVSS score of 8.1, is a spoofing vulnerability rooted in a cross-site scripting (XSS) weakness within on-premise Exchange Server. An anonymous security researcher discovered and reported the issue. Microsoft has added the vulnerability to its active exploitation advisories and is providing a temporary mitigation through its Exchange Emergency Mitigation Service (EEMS) while a permanent fix is being prepared.
What the Vulnerability Does
The flaw enables an attacker to conduct spoofing attacks via the Exchange web interface. The XSS component suggests it could be used to inject malicious scripts into mail sessions, intercept or manipulate user interactions within Outlook Web Access, or establish a foothold for further compromise of the Exchange environment. On-premise Exchange environments often sit at the centre of an organisation's identity and communication infrastructure, making them high-value targets for actors seeking persistence rather than immediate disruption.
CVE-2026-42897 is among the most heavily prioritised vulnerabilities in this week's patch cycle, appearing on the CISA Known Exploited Vulnerabilities catalogue alongside CVE-2026-42945 in NGINX, CVE-2026-44112 in OpenClaw, and CVE-2026-20182 in the Cisco Catalyst SD-WAN Controller.
What Is Known About Active Exploitation
Microsoft has confirmed active exploitation is occurring but has not disclosed the identity of the threat actor or actors involved, the scale of attacks, or whether any confirmed successful compromises have been identified. The specific attack chain being used in the wild has not been made public. This information gap is consistent with early-stage exploitation disclosures where threat intelligence is still being gathered.
Despite the limited operational detail, the combination of active exploitation and a publicly disclosed CVSS score of 8.1 places this in the category of vulnerabilities that enterprise security teams must act on immediately. Security firm Rapid7 has highlighted that vulnerabilities of this type are particularly attractive to sophisticated adversaries because they offer pre-positioning opportunities within trusted mail infrastructure.
Exchange as a Persistent Target
The use of Exchange Server as an attack vector is not new. On-premise Exchange has been among the most persistently targeted enterprise mail platforms for several years, exploited by nation-state actors including Russian APT groups and Chinese-affiliated threat clusters, with incidents ranging from the 2021 ProxyLogon campaign to more recent exploitation targeting Gulf-region government and financial sector deployments. The GCC cybersecurity landscape has seen consistent targeting of enterprise mail infrastructure, particularly in financial services and government sectors where legacy on-premise deployments remain common.
This vulnerability underscores a pattern that the Verizon Data Breach Investigations Report has consistently highlighted: vulnerability exploitation in enterprise software, particularly mail servers and network devices, remains one of the primary initial access vectors for both financially motivated and state-sponsored attackers.
Temporary Mitigation Available Now
Microsoft's Exchange Emergency Mitigation Service is delivering an interim mitigation automatically to Exchange servers with the service enabled. Security teams should verify that EEMS is active and confirm the mitigation has been applied. A permanent patch will follow in a scheduled or out-of-band security update.
Organisations running on-premise Exchange Server should treat this as a P0 item. Any Exchange deployment that is internet-facing and unmitigated is at elevated risk of active exploitation while the temporary fix is in place. Exchange servers not yet enrolled in EEMS should apply the manual mitigation steps outlined in Microsoft's security advisory.
Guidance for Gulf-Region Organisations
Enterprises across the GCC operating on-premise Exchange deployments, including government entities, financial institutions, and large corporates, should treat this disclosure as an active threat requiring immediate attention. Steps to take now include confirming EEMS is active, reviewing Exchange server logs for anomalous activity, and escalating to security operations teams to monitor for follow-on activity consistent with post-exploitation access.
The Microsoft Security Response Center is tracking this vulnerability and will publish patch availability as soon as a permanent fix is ready. Further Exchange security hardening guidance is available via Microsoft's Exchange security best practices documentation, which provides a useful baseline for on-premise deployments across the region.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.