news.mlab.sh
Back to the feed
threat-intel

Microsoft Exchange Zero-Day Under Attack, No Patch Available

High
Image: Dark Reading
Summary

A zero-day vulnerability (CVE-2026-42897) affecting Microsoft Exchange Outlook Web Access (OWA) is under active exploitation, allowing attackers to compromise mailboxes through cross-site scripting (XSS). Despite Microsoft's disclosure and the availability of mitigation strategies, a patch is not yet available, posing a significant risk to users and potentially leading to business email compromise or ransomware attacks.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.