Cybersecurity
Microsoft warns of Exchange zero-day flaw exploited in attacks
On Thursday, Microsoft shared mitigations for a high-severity Exchange Server vulnerability exploited in attacks that allow threat actors to execute arbitrary code via cross-site scripting (XSS) while targeting Outlook on the web users.
AI Summary
Microsoft issued mitigations for a high‑severity Exchange Server flaw (CVE‑2026‑42897) that was actively exploited. The vulnerability is a spoofing issue that lets attackers run arbitrary code through cross‑site scripting (XSS) against Outlook on the web users. It affects up‑to‑date versions of Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition. The company has provided guidance to patch or otherwise mitigate the risk.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedMore from Cybersecurity
Continue reading recent Cybersecurity coverage
- How AI Agents Can Trigger Runaway Costs for EnterprisesContinue reading
- BigCommerce alerts merchants of data breach linked to Ribon appsContinue reading
- CISA alerts of active exploitation of three Linux kernel flawsContinue reading
- ShinyHunters Hacked Clop. Now What About Clop's Victims?Continue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow