Cyber: Microsoft Exchange Zero-day Under Attack, No Patch Available (2026)

Cyber: Microsoft Exchange Zero-day Under Attack, No Patch Available (2026)

CVE-2026-42897 stems from a cross-site scripting (XSS) vulnerability and can allow an attacker to compromise Outlook Web Access (OWA) mailboxes.

Source: Dark Reading