Microsoft Patches Critical Exchange Server Zero-Day Vulnerability CVE-2026-42897
ID: d972fa84-da5f-51bd-abae-72060bad545c
STIX ID: report--d972fa84-da5f-51bd-abae-72060bad545c
Feed Name: ThreatCluster
Threat Score
Microsoft patched CVE-2026-42897, a high-severity cross-site scripting/spoofing zero-day in Exchange Server 2016, 2019, and Subscription Edition that enables unauthenticated remote execution of arbitrary JavaScript via Outlook Web Access; Microsoft released security updates in June 2026, CISA marked it as actively exploited and issued a patch deadline for U.S. agencies, and administrators are advised to apply patches and retain EEMS mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
