FeedMicrosoft Exchange Server 0-Day Vulnerability Exploited in A...
Cyber Security News

Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks Using Weaponized Email

📅 11 June 2026 at 08:27 UTC📰 Cyber Security NewsView original source ↗
Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks Using Weaponized Email

Microsoft has confirmed active exploitation of a new zero‑day spoofing flaw in on‑premises Exchange Server, tracked as CVE‑2026‑42897. The flaw allows attackers to execute arbitrary JavaScript in Outlook Web Access (OWA) simply by sending a weaponized email that a victim opens in a browser. On May 14, 2026, Microsoft disclosed CVE‑2026‑42897 as a spoofing vulnerability […] The post Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks Using Weaponized Email appeared first on Cyber Security News.

Read the full article

This is a curated summary. The complete article is available at Cyber Security News.

Read on Cyber Security News
← Back to feed