BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Microsoft Exchange Under Attack Via New XSS Bug

Microsoft warns of active Exchange Server exploit; urgent mitigation available.

  • Microsoft disclosed an actively exploited spoofing vulnerability tracked as CVE-2026-42897 in on-premise Exchange Server versions.
  • The flaw allows attackers to execute arbitrary JavaScript by sending a crafted email, exploitable through Outlook Web Access.
  • Mitigation is available via the Exchange Emergency Mitigation Service or a downloadable on-premises tool.

On May 15, 2026, Microsoft revealed a new cyber threat actively targeting on-premise installations of its Exchange Server software. This urgent security advisory, detailed by the company, warns of a spoofing vulnerability with a CVSS score of 8.1.

- Advertisement -

The vulnerability stems from a cross-site scripting flaw in web page generation. Consequently, an unauthorized attacker can perform spoofing over a network by sending a maliciously crafted email.

When the target opens this email in Outlook Web Access under specific conditions, it can trigger arbitrary JavaScript code execution in their browser. Microsoft has consequently assessed this flaw with an “Exploitation Detected” tag, confirming active in-the-wild use.

Microsoft is offering a temporary mitigation through its automated Exchange Emergency Mitigation Service. This service applies a URL rewrite configuration by default, while a permanent fix is being developed.

For air-gapped environments, the company advises administrators to download and run the Exchange on-premises Mitigation Tool. Instructions for applying the fix to single or all servers were provided in an elevated Exchange Management Shell.

- Advertisement -

The flaw impacts Exchange Server 2016, 2019, and Subscription Edition, but not Exchange Online. Microsoft‘s Exchange Team noted a cosmetic error message in the mitigation tool that does not affect its successful application.

However, specifics about the exploiting threat actor, attack scale, or successful compromises remain undisclosed. The company and security researchers strongly recommend implementing the provided mitigations immediately.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

FBI: Russia Phishes Signal Keys to Hijack Accounts

Russian intelligence actors are using sophisticated phishing to steal Signal Backup Recovery Keys, allowing...

Strategy’s STRC Hits Record Low, Now 29% Below Par Value

Strategy's STRC share price has plunged to a new all-time low of $71.25, nearly...

Linux ‘Pedit COW’ Flaw Lets Local Users Gain Root

A new Linux kernel vulnerability, CVE-2026-46331, allows local, unprivileged users to gain full root...

Google Stock Decline Deepens, Analyst Sees Rebound at $440

Alphabet's Google stock (NASDAQ: GOOG) has declined significantly since mid-May, falling from over $400.Analyst...

Corporate Treasuries Move Tokenized Cash to MMFs

Corporate treasuries are now using tokenized deposits to seamlessly move into higher-yielding tokenized money...

Must Read

Top 5 Best Crypto Faucets To Earn Free Crypto This Year

QUICK LINKSWhat Are Crypto Faucets and How Do They Work?How Do Crypto Faucets Make Money?What to Expect: Realistic EarningsThe Best Crypto Faucets of 2025:...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading