FeedVulnerabilityMicrosoft patches Exchange Server zero-day exploited in atta...
VulnerabilityBleeping Computer
6.1HIGH

Microsoft patches Exchange Server zero-day exploited in attacks

📅 10 June 2026 at 13:44 UTC📰 Bleeping ComputerView original source ↗
Microsoft patches Exchange Server zero-day exploited in attacks

Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A zero-day vulnerability in Microsoft Exchange Server (CVE-2026-42897) was exploited by threat actors, allowing them to execute arbitrary JavaScript code in cross-site scripting attacks targeting Outlook Web Access users. The vulnerability affects multiple versions of Exchange Server and can be exploited with no privileges.

⚙️Technical Details
CVEs
CVE-2026-42897
Affected Systems
Microsoft Exchange Server 2016Microsoft Exchange Server 2019Microsoft Exchange Server Subscription Edition (SE)
Attack Vectors
NETWORK
💥Impact Assessment
Severity: MEDIUM
🛡️Recommended Actions
1Deploy security updates from Microsoft as soon as possible
2Leave mitigations in place for additional protection
3Monitor systems for suspicious activity and implement additional security measures
📦Affected Products
Microsoft Exchange Server
🔐NVD Verified DataVERIFIED
CVE-2026-42897CVSS 6.1MEDIUM
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
Affected Products (CPE)
Microsoft Exchange Server

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed