{"id":246965,"date":"2026-05-15T08:06:00","date_gmt":"2026-05-15T12:06:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/15\/microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild\/"},"modified":"2026-05-15T23:45:10","modified_gmt":"2026-05-16T03:45:10","slug":"microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/15\/microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild\/","title":{"rendered":"Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild"},"content":{"rendered":"<p><a href=\"https:\/\/www.securityweek.com\/microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild\/\">Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild<\/a><\/p>\n<p><a href=\"https:\/\/www.securityweek.com\/microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild\/\">https:\/\/www.securityweek.com\/microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-15 08:06:00<\/a><\/p>\n<p>Source Domain: <a href=\"www.securityweek.com\">www.securityweek.com<\/a><\/p>\n<p><strong>Microsoft Exchange Server users are urged to immediately mitigate a newly disclosed zero-day vulnerability that has been exploited in attacks.<\/strong><\/p>\n<p>Microsoft this week patched 137 vulnerabilities with its Patch Tuesday updates and the cybersecurity industry was surprised to see that the latest updates did not address any zero-days. However, a zero-day was disclosed just 48 hours later, on May 14.<\/p>\n<p>The Exchange zero-day, tracked as CVE-2026-42897, has been described as a spoofing and XSS issue affecting Exchange Server Subscription Edition, 2016, and 2019.\u00a0<\/p>\n<p>\u201cImproper neutralization of input during web page generation (\u2018cross-site scripting\u2019) in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network,\u201d Microsoft said in its advisory.<\/p>\n<p>The company noted that the vulnerability affects Exchange Outlook Web Access (OWA) and an attacker can exploit it by sending a specially crafted email to the targeted user.<\/p>\n<p>\u201cIf the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context,\u201d Microsoft explained.<\/p>\n<p><span class=\"zox-ad-label\">Advertisement. Scroll to continue reading.<\/span><\/p>\n<p>Until a permanent patch is developed, Microsoft has shared a couple of mitigation options.<\/p>\n<p>Microsoft has not shared any information on the attacks exploiting CVE-2026-42897. SecurityWeek has reached out to the company for clarification and will update this article if it responds.<\/p>\n<p>An anonymous researcher has been credited for reporting the vulnerability.\u00a0<\/p>\n<p>It\u2019s not uncommon for threat actors to target Exchange Server vulnerabilities \u2014 CISA\u2019s KEV catalog currently lists nearly two dozen such flaws \u2014 but there do not appear to be any other reports of vulnerabilities discovered in 2025 and 2026 being exploited in the wild.\u00a0<\/p>\n<p>It\u2019s worth noting that CVE-2026-42897 has yet to be added to CISA\u2019s KEV list.<\/p>\n<p><strong>UPDATE: <\/strong>Microsoft has provided the following statement to&#8230;<\/p>\n<p><a href=\"https:\/\/www.securityweek.com\/microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild https:\/\/www.securityweek.com\/microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild\/ Publish Date: 2026-05-15 08:06:00&#8230;<\/p>\n","protected":false},"author":1,"featured_media":246966,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.securityweek.com\/wp-content\/uploads\/2026\/05\/Exchange.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,31,27],"class_list":["post-246965","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-exploit","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/246965"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=246965"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/246965\/revisions"}],"predecessor-version":[{"id":246967,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/246965\/revisions\/246967"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/246966"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=246965"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=246965"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=246965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}