CISA Adds Microsoft Exchange XSS Vulnerability to Known Exploited Vulnerabilities Catalog
The **Cybersecurity and Infrastructure Security Agency (CISA)** has added a new vulnerability, **CVE-2026-42897**, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects **Microsoft Exchange Server** and is a Cross-Site Scripting (XSS) flaw, frequently exploited by malicious actors.
The **Cybersecurity and Infrastructure Security Agency (CISA)** has added one new vulnerability to its [Known Exploited Vulnerabilities (KEV) Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog), based on evidence of active exploitation.
### CVE-2026-42897: Microsoft Exchange Server XSS
* [CVE-2026-42897](https://www.cve.org/CVERecord?id=CVE-2026-42897) **Microsoft Exchange Server** Cross-Site Scripting Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks.
### BOD 22-01 and Remediation
[Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities](https://www.cisa.gov/binding-operational-directive-22-01) established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the [BOD 22-01 Fact Sheet](https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf) for more information.
### Recommendation for All Organizations
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of [KEV Catalog vulnerabilities](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the [specified criteria](https://www.cisa.gov/known-exploited-vulnerabilities).