Skip to content

Microsoft Exchange Server 0

Cybersecuritynews Abinaya June 11, 2026

Microsoft has confirmed active exploitation of a new zero‑day spoofing flaw in on‑premises Exchange Server, tracked as CVE‑2026‑42897. The flaw allows attackers to execute arbitrary JavaScript in Outlook Web Access (OWA) simply by sending a weaponized email that a victim opens in a browser. On May 14, 2026, Microsoft disclosed CVE‑2026‑42897 as a spoofing vulnerability […]

Extracted Entities

Attack Types (1)

Companies (1)