Microsoft Exchange Zero-Day Under Attack, No Patch Available
ID: d765086c-458c-5d29-a661-aee9f76c056a
STIX ID: report--d765086c-458c-5d29-a661-aee9f76c056a
Feed Name: Dark Reading
Microsoft disclosed CVE-2026-42897, an actively exploited cross-site scripting zero-day in Exchange Outlook Web Access (OWA) affecting Exchange Server 2016, 2019, and Subscription Edition; successful exploitation can execute arbitrary JavaScript in the browser to access mailboxes, session tokens, and modify mailbox settings, enabling business email compromise or facilitating ransomware, and Microsoft recommends enabling the Exchange Emergency Mitigation Service or applying the updated Exchange On-premises Mitigation Tool while a security update is developed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
