HIGHVulnerability
Global

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

·Source: The Hacker News

Updated:

Executive Summary

Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue. "

Analysis

Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue. "

Indicators of Compromise (1)

CVE (1)
CVE-2026-42897
Source Attribution

Originally published by The Hacker News on May 15, 2026.

Related Threats