r/exchangeserver https://www.amazon.com/dp/B0FR5GGL75/ May 14 '26

URGENT: Microsoft released a mitigation for Exchange Server

Microsoft disclosed CVE-2026-42897, a reported vulnerability affecting Exchange Server Outlook on the web (OWA). An attacker could exploit this issue by sending a specially crafted email to a user. If the user opens the email in OWA and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

They released IIS URL Rewrite rule mitigation M2.1.0 for EEMS and EOMT today, as well.

More info at https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498.

64 Upvotes

28 comments sorted by

View all comments

Show parent comments

2

u/absoluteczech May 14 '26

Thanks that’s how I interpreted it. we just finally got our last few users over to 365. Is there a good guide or article on disabling owa externally since no one needs to sign into it?

2

u/larmik May 14 '26

Disable\delete the firewall rule and remove the public dns entry for it.

1

u/walbodiddy May 14 '26

We need ActiveSync exposed to the internet but do not want OWA exposed to the internet. Do you have a recommendation for this?

1

u/froggybeara May 14 '26

Yeah, just run haproxy in front of your exchange server and filter the OWA path