Actively exploited XSS zero-day in Exchange Server OWA (CVE-2026-42897). Microsoft released permanent patch KB5094139 on June 9, 2026. Exchange 2016/2019 require ESU Period 2. EEMS temporary mitigation, version table, SU installation procedure, exploitation detection, and Exchange Online migration recommendations.




