<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cve-2026-42897 on Daily DMARC News</title><link>https://news.excello.email/tags/cve-2026-42897/</link><description>Recent content in Cve-2026-42897 on Daily DMARC News</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Fri, 05 Jun 2026 08:00:00 +0000</lastBuildDate><atom:link href="https://news.excello.email/tags/cve-2026-42897/index.xml" rel="self" type="application/rss+xml"/><item><title>A Crafted Email Is All It Takes: CVE-2026-42897 Puts Exchange OWA Under Active Attack</title><link>https://news.excello.email/posts/2026-06-05-exchange-cve-2026-42897-owa-spoofing-dmarc-defense/</link><pubDate>Fri, 05 Jun 2026 08:00:00 +0000</pubDate><guid>https://news.excello.email/posts/2026-06-05-exchange-cve-2026-42897-owa-spoofing-dmarc-defense/</guid><description>&lt;p&gt;On May 14, 2026, Microsoft disclosed CVE-2026-42897, a spoofing vulnerability in on-premises Exchange Server affecting Outlook Web Access. Within 24 hours, CISA added it to the Known Exploited Vulnerabilities catalog. Within 15 days, the federal remediation deadline passed. As of today, there is still no permanent patch.&lt;/p&gt;
&lt;p&gt;The attack vector is an email.&lt;/p&gt;
&lt;h2 id="what-cve-2026-42897-does"&gt;What CVE-2026-42897 Does&lt;/h2&gt;
&lt;p&gt;The vulnerability is a cross-site scripting flaw in Exchange Server&amp;rsquo;s OWA component. Its CVSS score is 8.1, placing it in the high-severity tier. The attack chain is direct: an attacker sends a specially crafted email to a target who uses Outlook Web Access to read their mail. When the target opens that email in OWA, the malicious content triggers an XSS payload that executes arbitrary JavaScript in the victim&amp;rsquo;s browser context.&lt;/p&gt;</description></item></channel></rss>