Exchange Server is Microsoft's on-premises email and collaboration platform used by organizations to manage email, calendars, and contacts.
Overview
Exchange Server is Microsoft's on-premises email and collaboration platform used by organizations to manage email, calendars, and contacts. It provides APIs such as Exchange Web Services (EWS) for programmatic access and integrates with Outlook; its widespread deployment and rich surface area make it a high-value target and subject to rapid changes in authentication, client support, and patch management.
Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Microsoft SharePoint Attacks: Over 400 Victims Including US Agencies
A series of attacks exploiting zero-day vulnerabilities in Microsoft SharePoint has compromised over 400 organizations, including multiple US government agencies. The attacks, attributed to Chinese threat groups such as…
2 articles · Updated August 12, 2026 -
July 2026 Security Update: Record CVEs and Critical Vulnerabilities
In July 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe issued 12 bulletins for 88 unique CVEs, with a focus on ColdFusion and Commerce patches, including a…
3 articles · Updated July 14, 2026 -
Microsoft Patches Critical Exchange Server Zero-Day Vulnerability CVE-2026-42897
Microsoft has patched a high-severity zero-day vulnerability in Exchange Server, tracked as CVE-2026-42897, which allows attackers to execute arbitrary JavaScript via crafted emails in Outlook Web Access. The flaw…
27 articles · Updated June 11, 2026 -
Microsoft's Record Patch Tuesday in June 2026 Addresses 206 Vulnerabilities
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that…
215 articles · Updated July 1, 2026 -
Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
57 articles · Updated June 9, 2026 -
Exchange Server August 2026 Update Disables OWA Light and Addresses Vulnerabilities
Microsoft's August 2026 Exchange Server security update permanently disables the OWA Light client across all servers. This update addresses an authentication-bypass vulnerability demonstrated at Pwn2Own, affecting…
2 articles · Updated August 12, 2026 -
Anthropic's Claude Mythos Preview Sparks Cybersecurity Revolution
Anthropic has announced the launch of Project Glasswing, utilizing its unreleased AI model, Claude Mythos Preview, to identify and exploit thousands of critical software vulnerabilities across major operating systems…
1386 articles · Updated April 7, 2026 -
Active Exploitation of CVE-2026-42897 in Microsoft Exchange Server
Microsoft has disclosed a critical vulnerability, CVE-2026-42897, affecting on-premises Exchange Server versions 2016, 2019, and Subscription Edition. This zero-day flaw allows attackers to execute arbitrary JavaScript…
39 articles · Updated May 15, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1433 articles · Updated February 9, 2026
Recent Intelligence Reports
- ZDI August 2026 analysis — www.zerodayinitiative.com · August 13, 2026
- CNBC: Microsoft: Chinese hacking groups were part of SharePoint attacks — www.cnbc.com · August 13, 2026
- Lazarus Group Exploited Windows Zero — Finance.Biggo · August 12, 2026
- Exchange Server August 2026 update disables OWA Light and fixes Pwn2Own bug — Feeds.4Sysops · August 12, 2026
- The July 2026 Security Update Review — www.zerodayinitiative.com · July 30, 2026
- The July 2026 Security Update Review — Thezdi · July 14, 2026
- CVE 2023 23397script Doc — aka.ms · June 17, 2026
- Exploiting Cve 2023 23397 Microsoft Outlook Elevation Of Privilege Vulnerability — www.mdsec.co.uk · June 17, 2026