Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Microsoft patches Exchange Server zero-day exploited in attacks

0
Low
Published: Wed Jun 10 2026 (06/10/2026, 13:44:19 UTC)
Source: Bleeping Computer

Description

Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users. [...]

Affected software

Affected versions
>=2016 <2016.9999>=2019 <2019.9999>=SubscriptionEdition <SubscriptionEdition.9999

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/10/2026, 13:49:51 UTC

Technical Analysis

CVE-2026-42897 is a high-severity cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016, 2019, and Subscription Edition. It allows remote attackers to execute arbitrary JavaScript code in the context of Outlook Web Access by sending a specially crafted email. The vulnerability was actively exploited before patching. Microsoft initially deployed an automatic temporary mitigation via the Exchange Emergency Mitigation Service (EEMS) and later released official security updates in June 2026. The vendor strongly advises applying these updates promptly and retaining the mitigation to ensure continuous protection. The U.S. CISA added this vulnerability to its exploited-in-the-wild list and required government agencies to patch quickly. This vulnerability requires no privileges and can be triggered by user interaction with a malicious email in Outlook Web Access.

Potential Impact

The vulnerability enables remote attackers to execute arbitrary JavaScript code in the browser of Outlook Web Access users, potentially leading to spoofing and other XSS-related impacts. Because exploitation requires no privileges and only user interaction with a crafted email, the risk of compromise is significant for affected Exchange Server environments. The vulnerability was actively exploited in the wild prior to patching, increasing the urgency of remediation. The impact is limited to Outlook Web Access users on affected Exchange Server versions.

Mitigation Recommendations

Microsoft has released official security updates for Exchange Server 2016, 2019, and Subscription Edition to address this vulnerability. Administrators should deploy these June 2026 security updates as soon as possible. Additionally, Microsoft recommends maintaining the previously deployed Exchange Emergency Mitigation Service (EEMS) temporary mitigation to provide an additional layer of defense. No further action beyond applying the patch and retaining the mitigation is indicated by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-exchange-server-zero-day-exploited-in-attacks/","fetched":true,"fetchedAt":"2026-06-10T13:49:44.312Z","wordCount":664}

Threat ID: 6a296b78c9170919df24460a

Added to database: 6/10/2026, 1:49:44 PM

Last enriched: 6/10/2026, 1:49:51 PM

Last updated: 6/10/2026, 7:29:24 PM

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses