Skip to main content
Father's Day Sale — Get 40% off Vantage for yourself or as a gift
Published loading...Updated

Microsoft Confirms Active 0-Day Exploit—Check Emergency Mitigation Now

Microsoft said Exchange Emergency Mitigation Service will automatically protect on-premises servers while permanent fixes are still pending.

  • On Thursday, Microsoft released mitigations for CVE-2026-42897, a high-severity Exchange Server spoofing vulnerability that allows attackers to execute arbitrary JavaScript in Outlook Web Access via specially crafted emails.
  • The vulnerability affects up-to-date Exchange Server and Exchange Server Subscription Edition software. The Exchange Team stated, "An attacker could exploit this issue by sending a specially crafted email to a user."
  • Organizations should enable the Exchange Emergency Mitigation Service for automatic protection, while Admins with air-gapped servers can apply mitigations manually using the Mitigation Tool via the Exchange Management Shell with specific commands for all servers.
  • Applying these measures causes issues, including broken OWA Print Calendar functionality and display problems for inline images, while Microsoft plans future patches requiring enrollment in the Period Exchange Server ESU program for older releases.
  • EEMS was introduced in September 2021 to provide automated protection against high-risk threats following massive attacks involving ProxyLogon and ProxyShell; CISA and the National Security Agency released guidance to help Admins harden Microsoft Exchange servers after support ended.
Insights by Ground AI
Podcasts & Opinions

16 Articles

In Microsoft's Exchange, there's a zero-day gap that already abuses attackers. Admins should act quickly.

·Germany
Read Full Article

A critical vulnerability currently threatens numerous local Exchange servers. Attackers can execute malicious code via prepared emails. A final patch is missing, which puts IT managers before difficult decisions. (Read more)

Microsoft has confirmed the active exploitation of the CVE-2026-42897 vulnerability in the Exchange Server, placing administrators and security teams on alert. Failure, classified as zero-day, is already being used in real attacks even before the availability of a definitive patch. The problem affects local environments of the Exchange Server and allows attacks involving Outlook Web Access (OWA) through a Cross-Site Scripting (XSS) vulnerability…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe
Father's Day SaleGet 40% off Vantage subscriptions for yourself or a friend.Get Started

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news on Friday, May 15, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal