logo

Microsoft Exchange Zero-Day Under Attack, No Patch Available

ID: d765086c-458c-5d29-a661-aee9f76c056a

STIX ID: report--d765086c-458c-5d29-a661-aee9f76c056a

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Rob Wright

...
...

Microsoft disclosed CVE-2026-42897, an actively exploited cross-site scripting zero-day in Exchange Outlook Web Access (OWA) affecting Exchange Server 2016, 2019, and Subscription Edition; successful exploitation can execute arbitrary JavaScript in the browser to access mailboxes, session tokens, and modify mailbox settings, enabling business email compromise or facilitating ransomware, and Microsoft recommends enabling the Exchange Emergency Mitigation Service or applying the updated Exchange On-premises Mitigation Tool while a security update is developed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.