Microsoft Confirms Active 0-Day Exploit—Check Emergency Mitigation Now

TL;DR AI
2 min readKey summary
Microsoft disclosed CVE-2026-42897, a spoofing zero-day in on-premises Exchange Server that is being actively exploited.
CISA added the flaw to its Known Exploited Vulnerabilities Catalog after confirming real-world attacks.
Microsoft says affected organizations should enable Exchange Emergency Mitigation Service immediately.
The issue could expose enterprise email and identity systems, making fast mitigation critical for on-premises Exchange users.



