PHONES Huawei Leads China Smartphone Market as Apple Grows Amid 2% Decline GAMES Phasmophobia Gets Deildegast Ghost and 13 Willow Street Rework STEAM Fallout 76 Update 2.28 Released: Infestations Rebalanced and Boss Loot Fixed GAMES Former Forza Director Calls Xbox Game Pass ‘A Real Shame’ GAMES Bethesda Takes Fallout 76 Servers Offline for July 21 Title Update INTEL Kirin 9030 Pro Teardown Shows SMIC N+3 Beats Intel 18A Pitch PLAYSTATION 5 Wreckreation 2 Announced for PS5, Xbox Series, and PC NINTENDO SWITCH Dear Passengers Console Status: PS, Xbox, PC, and Switch Availability XBOX SERIES X Xbox Game Pass Adds 6 New Games in July 2026, Including Halo GAMES Xbox Game Pass Price Cuts to $22.99 as Seven New Titles Join Service GAMES Hunty Zombie July 2026 Reward Codes: Free Items for Roblox Players GAMES Dear Passengers Release News & Demo Details for 2026 Launch HANDHELD GAMING Anbernic RG SP Launches with GBA SP Design and Thinner Chassis NINTENDO SWITCH ASYLUM Console Release Brings Horror Adventure to PS5, Xbox, Switch

Microsoft Exchange Server Zero-Day CVE-2026-42897 Exploited via Crafted Email

Owen Carter 0 comments 1 min read

Microsoft confirms active exploitation of CVE-2026-42897, a zero-day XSS vulnerability in on-premises Exchange Server. Emergency mitigation deployed; no permanent patch yet. CISA adds to KEV catalog.

Microsoft Exchange Server Zero-Day CVE-2026-42897 Exploited via Crafted Email
SOFTWARE AND UPDATES

Microsoft has confirmed active exploitation of a zero-day vulnerability in on-premises Exchange Server. The flaw, tracked as CVE-2026-42897, allows attackers to execute arbitrary JavaScript in a victim's browser by sending a crafted email. No permanent patch is available yet.

Zero-day XSS flaw in OWA

The vulnerability is a cross-site scripting issue in the Outlook Web Access component, rated CVSS 8.1. It affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition at any update level. Exchange Online is not vulnerable.

Microsoft deployed an emergency mitigation on May 14 through the Exchange Emergency Mitigation Service, labeled M2.1.x. The mitigation disables the OWA Print Calendar feature, inline images, and the OWA Light interface. CISA added the flaw to its Known Exploited Vulnerabilities catalog on May 15 and requires federal agencies to remediate by May 29.

Microsoft is developing a permanent fix but has not confirmed a release timeline. The company has not identified the threat actors behind the attacks or disclosed which organizations were targeted.

Source: NotebookCheck

Discussion

0 comments

Leave a comment