Unpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897)
ID: aca0c389-efa9-5979-9459-110f646d9784
STIX ID: report--aca0c389-efa9-5979-9459-110f646d9784
Feed Name: Help Net Security
Threat Score
Microsoft warns that CVE-2026-42897, a critical cross-site scripting (XSS) vulnerability in on-premises Microsoft Exchange Server (Subscription Edition RTM, 2019, and 2016), is being actively exploited via specially crafted emails opened in Outlook Web Access; Microsoft has published temporary mitigations and plans security updates for affected Exchange builds while Exchange Online is not affected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
