Switch language한국어
Back to the list

Microsoft Confirms Active 0-Day Exploit—Check Emergency Mitigation Now

TL;DR AI

Key summary

2 min read
  1. Microsoft disclosed CVE-2026-42897, a spoofing zero-day in on-premises Exchange Server that is being actively exploited.

  2. CISA added the flaw to its Known Exploited Vulnerabilities Catalog after confirming real-world attacks.

  3. Microsoft says affected organizations should enable Exchange Emergency Mitigation Service immediately.

  4. The issue could expose enterprise email and identity systems, making fast mitigation critical for on-premises Exchange users.

Read the original