logo

Microsoft warns of Exchange zero-day flaw exploited in attacks

ID: 011cf5a3-55cb-5769-973f-a85bf1ba5a5b

STIX ID: report--011cf5a3-55cb-5769-973f-a85bf1ba5a5b

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Sergiu Gatlan

...
...

Microsoft disclosed CVE-2026-42897, a high-severity spoofing/XSS vulnerability in Exchange Server 2016, 2019, and Subscription Edition that is being exploited in the wild to execute arbitrary JavaScript when victims open specially crafted emails in Outlook on the web; Microsoft recommends enabling the Exchange Emergency Mitigation Service (EEMS) or applying the Exchange on‑premises Mitigation Tool (EOMT) as temporary protections while patches are prepared, noting mitigation side-effects and limited patch availability for some older supported releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.