Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

    May 15, 2026

    Sodium Ion Batteries Can Reach 100 Gigawatt Per Hour Per Year Scale in 2027

    May 15, 2026

    Lenovo launches a budget 200Hz gaming monitor

    May 15, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild
    Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild
    Cybersecurity

    Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

    The Tech GuyBy The Tech GuyMay 15, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Microsoft Exchange Server users are urged to immediately mitigate a newly disclosed zero-day vulnerability that has been exploited in attacks.

    Advertisement

    Microsoft this week patched 137 vulnerabilities with its Patch Tuesday updates and the cybersecurity industry was surprised to see that the latest updates did not address any zero-days. However, a zero-day was disclosed just 48 hours later, on May 14.

    The Exchange zero-day, tracked as CVE-2026-42897, has been described as a spoofing and XSS issue affecting Exchange Server Subscription Edition, 2016, and 2019. 

    “Improper neutralization of input during web page generation (‘cross-site scripting’) in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network,” Microsoft said in its advisory.

    The company noted that the vulnerability affects Exchange Outlook Web Access (OWA) and an attacker can exploit it by sending a specially crafted email to the targeted user.

    “If the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context,” Microsoft explained.

    Advertisement. Scroll to continue reading.

    Until a permanent patch is developed, Microsoft has shared a couple of mitigation options.

    Microsoft has not shared any information on the attacks exploiting CVE-2026-42897. SecurityWeek has reached out to the company for clarification and will update this article if it responds.

    An anonymous researcher has been credited for reporting the vulnerability. 

    It’s not uncommon for threat actors to target Exchange Server vulnerabilities — CISA’s KEV catalog currently lists nearly two dozen such flaws — but there do not appear to be any other reports of vulnerabilities discovered in 2025 and 2026 being exploited in the wild. 

    It’s worth noting that CVE-2026-42897 has yet to be added to CISA’s KEV list.

    UPDATE: Microsoft has provided the following statement to SecurityWeek:

    “We have issued CVE-2026-42897 to address a spoofing vulnerability affecting Exchange Outlook Web Access (OWA). We recommend customers enable EEMS to be better protected and to follow our guidance available here.”

    Related: Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises

    Related: Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026

    Related: Ivanti Patches EPMM Zero-Day Exploited in Targeted Attacks

    Related: Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws

    May 15, 2026

    American Lending Center Data Breach Affects 123,000 Individuals

    May 15, 2026

    Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere

    May 15, 2026

    New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation

    May 14, 2026

    Enhancing Data Center Security Without Sacrificing Performance

    May 14, 2026

    F5 Patches Over 50 Vulnerabilities

    May 14, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views

    ChatGPT Group Chats are here … but not for everyone (yet)

    November 14, 20258 Views

    Facebook updates its algorithm to give users more control over which videos they see

    October 8, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

    May 15, 2026

    Sodium Ion Batteries Can Reach 100 Gigawatt Per Hour Per Year Scale in 2027

    May 15, 2026

    Lenovo launches a budget 200Hz gaming monitor

    May 15, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.