Bleepingcomputer
Microsoft Patches Critical Exchange Server Zero-Day Vulnerability CVE-2026-42897
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Microsoft has patched a high-severity zero-day vulnerability in Exchange Server, tracked as CVE-2026-42897, which allows attackers to execute arbitrary JavaScript via crafted emails in Outlook Web Access. The flaw affects Exchange Server 2016, 2019, and Subscription Edition, enabling remote exploitation without user privileges. Microsoft disclosed the vulnerability on May 14, 2026, and it was added to CISA's list of actively exploited vulnerabilities the following day. Security updates were released on June 10, 2026, with strong recommendations for immediate deployment. The Cybersecurity and Infrastructure Security Agency has ordered U.S. government agencies to patch their systems by May 29, 2026. This vulnerability is part of a troubling trend, as CISA has previously added 20 Microsoft Exchange vulnerabilities to its exploited list in the last five years.
Key Points: • CVE-2026-42897 allows remote execution of JavaScript via Outlook Web Access. • Microsoft released security updates on June 10, 2026, urging immediate deployment. • CISA ordered U.S. agencies to patch affected Exchange servers by May 29, 2026.