Microsoft patches Exchange Server zero-day exploited in attacks
ID: 5ed223a6-d2c4-516f-8460-860939acc7f9
STIX ID: report--5ed223a6-d2c4-516f-8460-860939acc7f9
Feed Name: Bleeping Computer
Threat Score
Microsoft patched an actively exploited high-severity Exchange Server XSS vulnerability (CVE-2026-42897) that can execute arbitrary JavaScript in Outlook Web Access when a user opens a specially crafted email; Microsoft deployed temporary mitigations through EEMS and released June 2026 security updates while CISA added the flaw to its list of vulnerabilities exploited in the wild and ordered US government agencies to patch within two weeks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
