Back Feeds.4Sysops Microsoft patches actively exploited Exchange Server XSS vulnerability
Microsoft has released critical security updates to address CVE-2026-42897, a cross-site scripting vulnerability in Exchange Server that is currently being exploited. The flaw affects Exchange Server 2016, 2019, and the Subscription Edition when users access their mail via Outlook Web Access. Attackers can trigger the vulnerability by sending a specially crafted email that executes arbitrary JavaScript code within the victim's browser context. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
