Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Exchange OWA XSS exposure: are your external mail controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: CVE-2026-42897 is an actively exploited XSS flaw in on-premises Exchange OWA that Microsoft rated 8.1 High and CISA added to KEV within one day, according to CYCOGNITO. The issue shows how internet-facing mail portals can turn a user click into browser-session compromise, mailbox access, and downstream phishing without attacker authentication.

NHIMG editorial — based on content published by CYCOGNITO: Sample of assets impacted by Exchange OWA XSS vulnerability

By the numbers:

Questions worth separating out

Q: What breaks when an internet-facing OWA endpoint is hit by XSS?

A: The immediate break is session trust.

Q: Why do on-premises Exchange servers remain risky after cloud migration?

A: Because many organisations keep residual servers for hybrid identity, migration coexistence, or special mailbox workflows, and those servers are often still internet-facing.

Q: How do security teams know if a mitigation is actually working?

A: They retest the exact attack path that proved the exposure in the first place.

Practitioner guidance

  • Verify EEMS or EOMT mitigation status Confirm whether supported Exchange servers have Exchange Emergency Mitigation Service enabled, whether the relevant mitigation has been applied, and whether older builds need manual EOMT use.
  • Inventory every internet-facing OWA endpoint List all externally reachable Exchange servers, including residual hybrid systems and older unsupported builds that may still be in service.
  • Hunt for abnormal mailbox and mail-flow behaviour Review OWA and mail logs for suspicious JavaScript execution indicators, unusual internal mail originating from user accounts, and mailbox actions that do not match normal user patterns.

What's in the full analysis

CYCOGNITO's full analysis covers the operational detail this post intentionally leaves for the source:

  • Asset-level exposure examples showing how internet-facing Exchange endpoints were identified across observed organisations
  • The specific mitigation workflow for supported Exchange builds, including EEMS coverage and manual EOMT use
  • Verification steps through the Exchange Health Checker report so teams can prove mitigation status
  • Defender guidance for OWA log review, browser-side hardening, and external access restriction during the exploitation window

👉 Read CYCOGNITO's analysis of CVE-2026-42897 and Exchange OWA exposure →

Exchange OWA XSS exposure: are your external mail controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Browser-context email exploits are identity incidents, not just application bugs. When OWA runs inside a domain-authenticated session, a single XSS can turn web rendering into account abuse, mailbox access, and trusted internal phishing. That makes the governance problem squarely about session trust, not only secure coding. Practitioners should treat externally published mail interfaces as identity-sensitive control points, not generic web apps.

A few things that frame the scale:

  • From our research: When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, according to LLMjacking: How Attackers Hijack AI Using Compromised NHIs.
  • DeepSeek accidentally embedded over 11,000 secrets in its training data and left a database exposed online, revealing more than one million sensitive records including chat histories, backend credentials, and API keys.

A question worth separating out:

Q: Who is accountable when an exploited platform flaw exposes user mail or trusted access?

A: Accountability is shared across vulnerability management, platform ownership, and identity governance. Patch teams close the code issue, but the business owner must confirm exposure was limited and identity teams should validate whether delegated access, sign-ins, or privileged sessions were abused. For regulated environments, evidence of timely triage and access review matters as much as the patch itself.

👉 Read our full editorial: Exchange OWA XSS exposure shows the risk in on-prem email



   
ReplyQuote
Share: