Skip to content
Microsoft Warns of Exchange Zero-Day Flaw Exploited in Attacks

Microsoft Warns of Exchange Zero-Day Flaw Exploited in Attacks

Ground.News May 15, 2026

On Thursday, Microsoft shared mitigations for a high-severity Exchange Server vulnerability exploited in attacks that allow threat actors to execute arbitrary code via cross-site scripting (XSS) while targeting Outlook on the web users.

Microsoft has confirmed the active exploitation of the CVE-2026-42897 vulnerability in the Exchange Server, placing administrators and security teams on alert. Failure, classified as zero-day, is already being used in real attacks even before the availability of a definitive patch. The problem affects local environments of the Exchange Server and allows attacks involving Outlook Web Access (OWA) through a Cross-Site Scripting (XSS) vulnerability…

Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions.

A critical XSS vulnerability (CVE-2026-42897) in Microsoft Exchange Server is being exploited by attackers, Microsoft warned on Thursday.

Key Takeaways: A newly disclosed Exchange Server flaw could expose organizations to serious browser-based attacks. Microsoft has released temporary mitigations while administrators wait for a full security patch. Some Outlook Web Access features may be impacted after applying the recommended protections. Microsoft has disclosed a critical vulnerability in on-premises Exchange Server that allows attackers to execute malicious code through specia…

Microsoft issued an urgent security alert regarding a newly discovered vulnerability in Exchange Server that is currently being exploited in the wild. Tracked as CVE-2026-42897, this critical spoofing flaw carries a high CVSS 3.1 severity score of 8.1 and directly impacts on-premises email infrastructure. Threat actors are actively exploiting this network-based weakness to compromise organizational systems before a permanent patch is finalized. …

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage

Extracted Entities

Attack Types (1)

Vulnerabilities (1)