logo

Microsoft Patches Critical Exchange Server Zero-Day Vulnerability CVE-2026-42897

ID: d972fa84-da5f-51bd-abae-72060bad545c

STIX ID: report--d972fa84-da5f-51bd-abae-72060bad545c

Feed Name: ThreatCluster

Threat Score
74/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

...
...

Microsoft patched CVE-2026-42897, a high-severity cross-site scripting/spoofing zero-day in Exchange Server 2016, 2019, and Subscription Edition that enables unauthenticated remote execution of arbitrary JavaScript via Outlook Web Access; Microsoft released security updates in June 2026, CISA marked it as actively exploited and issued a patch deadline for U.S. agencies, and administrators are advised to apply patches and retain EEMS mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.