threat-intel
Microsoft Exchange Zero-Day Under Attack, No Patch Available
High
Summary
A zero-day vulnerability (CVE-2026-42897) affecting Microsoft Exchange Outlook Web Access (OWA) is under active exploitation, allowing attackers to compromise mailboxes through cross-site scripting (XSS). Despite Microsoft's disclosure and the availability of mitigation strategies, a patch is not yet available, posing a significant risk to users and potentially leading to business email compromise or ransomware attacks.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
