Switch language한국어
Back to the list

Microsoft Confirms Active 0-Day Exploit—Check Emergency Mitigation

TL;DR AI

Key summary

2 min read
  1. Microsoft says Exchange Server CVE-2026-42897 is being actively exploited as a zero-day, prompting urgent action from defenders.

  2. CISA has added the flaw to its Known Exploited Vulnerabilities catalog after confirming real-world attacks.

  3. The bug could allow remote code execution or user spoofing on on-premises Exchange servers, risking email and network compromise.

  4. Microsoft advises organizations to enable the Exchange Emergency Mitigation Service and run the Health Checker script to verify protections while waiting for a patch.

Read the original