Story perspectives
Microsoft Rolls Out Fix for Outlook Web Access XSS Flaw
5/19/2026
1 of 3
Microsoft Deploys Mitigation
- Microsoft deployed mitigation (M2) for the exploited CVE-2026-42897 reflected XSS flaw in Outlook Web Access.
- The reflected XSS bug lets an unauthenticated attacker run JavaScript in an Outlook Web Access session via a crafted email.
- Exploitation can capture session tokens, spoof identities, and grant access, but it does not affect service availability.
- Admins must activate mitigation M2, apply it with the On-premises Tool when EEMS is off and boost monitoring.
1 / 3
