CISA Warns of Actively Exploited Microsoft Exchange Server Vulnerability
Another Microsoft Exchange Zero Day Is Under Active Exploitation As an independent cybersecurity blogger and part time penetration tester, Microsoft Exchange Server continues to remain one of the most heavily targeted enterprise platforms in cybersecurity history. CISA and Microsoft are now warning organizations about a newly disclosed and actively exploited vulnerability affecting: Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Exchange Server Subscription Edition The flaw, tracked as: CVE-2026-42897 CVSS score: 8.1 High affects Outlook Web Access (OWA) and allows attackers to execute malicious JavaScript within a victim’s browser session through specially crafted emails. Researchers warn the vulnerability is already being exploited in the wild. What Happened: Microsoft Confirmed Active Exploitation Microsoft disclosed CVE-2026-42897 on May 14, 2026 and classified the issue with: “Exploitation Detected” status. According to Microsoft, ...