
Cybersecurity
Microsoft Exchange Zero-Day Under Attack
A new zero-day vulnerability in Microsoft Exchange, identified as CVE-2026-42897, is being actively exploited. The flaw is a cross-site scripting (XSS) issue that allows attackers to compromise Outlook Web Access (OWA) mailboxes. Microsoft has not yet released a patch to fix the vulnerability.
Dark Reading1 min read