← Front PageVulnerabilities Desk
Vulnerabilities
Microsoft Exchange Zero-Day Under Attack, No Patch Available
Active exploitation window opens for European enterprises using Exchange OWA while Microsoft develops emergency patch response.
Summary written by editorial AI · Source link below
CVSS8.1highCVE-2026-42897
CVE-2026-42897 stems from a cross-site scripting (XSS) vulnerability and can allow an attacker to compromise Outlook Web Access (OWA) mailboxes.
Continue at the source
Read the full report at Dark ReadingExternal link — opens at Dark Reading in a new tab.
§
Continue with
More from the Vulnerabilities Desk
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores2d
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code2d
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities3d
- Government Rails Site Hit Hours After CVE Patch3d
- Critical Citrix NetScaler auth bypass now leveraged in attacks3d