CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day
ID: 3a94d948-12ef-5733-ac5f-9deecaf5b663
STIX ID: report--3a94d948-12ef-5733-ac5f-9deecaf5b663
Feed Name: Security Affairs
Threat Score
Microsoft confirmed active exploitation of a high-severity Exchange Server zero-day (CVE-2026-42897, CVSS 8.1) that enables cross-site scripting via specially crafted emails in Outlook Web Access; Microsoft released temporary mitigations while a permanent patch is prepared, and the advisory warns of the high impact and exposure of Exchange servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
