Bleepingcomputer Microsoft Patches Critical Exchange Server Zero-Day Vulnerability CVE-2026-42897
Article Content
- •CVE-2026-42897 allows remote execution of JavaScript via Outlook Web Access.
- •Microsoft released security updates on June 10, 2026, urging immediate deployment.
- •CISA ordered U.S. agencies to patch affected Exchange servers by May 29, 2026.
Microsoft has patched a high-severity zero-day vulnerability in Exchange Server, tracked as CVE-2026-42897, which allows attackers to execute arbitrary JavaScript via crafted emails in Outlook Web Access. The flaw affects Exchange Server 2016, 2019, and Subscription Edition, enabling remote exploitation without user privileges. Microsoft disclosed the vulnerability on May 14, 2026, and it was added to CISA's list of actively exploited vulnerabilities the following day. Security updates were released on June 10, 2026, with strong recommendations for immediate deployment. The Cybersecurity and Infrastructure Security Agency has ordered U.S. government agencies to patch their systems by May 29, 2026. This vulnerability is part of a troubling trend, as CISA has previously added 20 Microsoft Exchange vulnerabilities to its exploited list in the last five years.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (27)
Following this threat?
Track Microsoft and CVE-2020-0688 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Stored XSS Vulnerabilities Found in SiYuan Versions Before 3.7.4 Two critical vulnerabilities, CVE-2026-73050 and CVE-2026-73052, have been identified in SiYuan versions prior to 3.7.4. CVE-2026-73050 allows attackers to exploit stored cross-site scripting (XSS) via unescaped color fields in select options, executing arbitrary JavaScript in victim browsers. CVE-2026-73052 enables…