Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    DentaQuest Data Breach Potentially Impacts Over 23 Million People

    July 27, 2026

    Father-Son Duo Accused of Kidnapping Government Biologists Who Were Out Studying Frogs

    July 27, 2026

    Google Maps’ biggest Android Auto upgrade is reaching more users

    July 27, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild
    Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild
    Cybersecurity

    Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

    The Tech GuyBy The Tech GuyMay 15, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Microsoft Exchange Server users are urged to immediately mitigate a newly disclosed zero-day vulnerability that has been exploited in attacks.

    Advertisement

    Microsoft this week patched 137 vulnerabilities with its Patch Tuesday updates and the cybersecurity industry was surprised to see that the latest updates did not address any zero-days. However, a zero-day was disclosed just 48 hours later, on May 14.

    The Exchange zero-day, tracked as CVE-2026-42897, has been described as a spoofing and XSS issue affecting Exchange Server Subscription Edition, 2016, and 2019. 

    “Improper neutralization of input during web page generation (‘cross-site scripting’) in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network,” Microsoft said in its advisory.

    The company noted that the vulnerability affects Exchange Outlook Web Access (OWA) and an attacker can exploit it by sending a specially crafted email to the targeted user.

    “If the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context,” Microsoft explained.

    Advertisement. Scroll to continue reading.

    Until a permanent patch is developed, Microsoft has shared a couple of mitigation options.

    Microsoft has not shared any information on the attacks exploiting CVE-2026-42897. SecurityWeek has reached out to the company for clarification and will update this article if it responds.

    An anonymous researcher has been credited for reporting the vulnerability. 

    It’s not uncommon for threat actors to target Exchange Server vulnerabilities — CISA’s KEV catalog currently lists nearly two dozen such flaws — but there do not appear to be any other reports of vulnerabilities discovered in 2025 and 2026 being exploited in the wild. 

    It’s worth noting that CVE-2026-42897 has yet to be added to CISA’s KEV list.

    UPDATE: Microsoft has provided the following statement to SecurityWeek:

    “We have issued CVE-2026-42897 to address a spoofing vulnerability affecting Exchange Outlook Web Access (OWA). We recommend customers enable EEMS to be better protected and to follow our guidance available here.”

    Related: Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises

    Related: Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026

    Related: Ivanti Patches EPMM Zero-Day Exploited in Targeted Attacks

    Related: Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    DentaQuest Data Breach Potentially Impacts Over 23 Million People

    July 27, 2026

    Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

    July 25, 2026

    Abstract Raises $25 Million to Expand Composable Security Operations Platform

    July 25, 2026

    Rockwell Patches Code Execution Flaws in Arena Simulation Software

    July 25, 2026

    Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday

    July 25, 2026

    AegisAI Raises $36 Million for AI-Powered Email Security

    July 24, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026306 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026187 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    DentaQuest Data Breach Potentially Impacts Over 23 Million People

    July 27, 2026

    Father-Son Duo Accused of Kidnapping Government Biologists Who Were Out Studying Frogs

    July 27, 2026

    Google Maps’ biggest Android Auto upgrade is reaching more users

    July 27, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.