logo

Microsoft patches Exchange Server zero-day exploited in attacks

ID: 5ed223a6-d2c4-516f-8460-860939acc7f9

STIX ID: report--5ed223a6-d2c4-516f-8460-860939acc7f9

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Sergiu Gatlan

...
...

Microsoft patched an actively exploited high-severity Exchange Server XSS vulnerability (CVE-2026-42897) that can execute arbitrary JavaScript in Outlook Web Access when a user opens a specially crafted email; Microsoft deployed temporary mitigations through EEMS and released June 2026 security updates while CISA added the flaw to its list of vulnerabilities exploited in the wild and ordered US government agencies to patch within two weeks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.