logo

U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog

ID: ba6f2c9b-40d4-5f00-9935-f7e7a6cad8f3

STIX ID: report--ba6f2c9b-40d4-5f00-9935-f7e7a6cad8f3

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: Pierluigi Paganini

...
...

CISA added Microsoft Exchange Server CVE-2026-42897 (CVSS 8.1), an Outlook Web Access cross-site scripting zero-day actively exploited in the wild, to its Known Exploited Vulnerabilities catalog; Microsoft confirmed active exploitation, released temporary mitigations, and federal agencies are ordered to remediate by May 29, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.