Skip to content
CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero

CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero

Securityaffairs.Co •Pierluigi Paganini • May 15, 2026

Microsoft warned that attackers are exploiting a new Exchange Server zero-day vulnerability, tracked as CVE-2026-42897, in the wild. Microsoft warned that threat actors are actively exploiting a new Exchange Server zero-day vulnerability tracked as CVE-2026-42897 (CVSS score 8.1). The vulnerability is an improper neutralization of input during web page generation (‘cross-site scripting’) in Microsoft Exchange […]

Extracted Entities

Attack Types (1)

Platforms (1)