By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Microsoft Exchange: Zero-day vulnerability is under attack
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Software > Microsoft Exchange: Zero-day vulnerability is under attack
Software

Microsoft Exchange: Zero-day vulnerability is under attack

News Room
Last updated: 2026/05/15 at 5:50 PM
News Room Published 15 May 2026
Share
Microsoft Exchange: Zero-day vulnerability is under attack
SHARE

Microsoft warns of a zero-day vulnerability in Exchange that is already being attacked in the wild. Updated software is not yet available. However, Microsoft offers countermeasures that admins should implement as quickly as possible.

Read more after the ad

In the vulnerability description, Microsoft explains that it is due to insufficient filtering of input when generating web pages, a cross-site scripting vulnerability. This allows unauthenticated attackers from the network to carry out spoofing attacks (CVE-2026-42897, CVSS 8.1Risk „hoch“). However, Microsoft classifies the severity as “critical“A blog post from Microsoft’s Exchange team explains this and the countermeasures in more detail.

Attack scenario

The vulnerability appears to specifically affect Outlook Web Access (OWA). Microsoft states that attackers can send manipulated emails to victims. When users open the email in OWA and certain, unspecified interaction conditions are met, arbitrary JavaScript is then executed in the browser.

Exchange Server 2016, 2019 and Exchange Server Subscription Edition (SE) are affected in any update level. However, Microsoft does not provide software updates. However, an automatic fix is ​​available through the Exchange Emergency Mitigation (EM) service. Where the service is active, Microsoft has already applied the countermeasures. The service has been distributed since September 2021 and is activated by default. In the blog post, Microsoft also shows a manual variant.

The countermeasures to contain the CVE-2026-42897 vulnerability have some side effects that admins should be aware of. Printing calendars in OWA may no longer work. Inline images are no longer displayed correctly in the receiver panel. OWA Light could no longer function properly – but that is old iron and “deprecated” anyway. The countermeasure also shows in the mitigation details that it is invalid for the current Exchange version – purely cosmetic, the Redmond company assures. If “Applied” is displayed as the status, it has been effectively applied.

The Exchange team is currently working on a permanent, proper fix. This will appear in the future as an update for Exchange SE RTM, Exchange 2016 CU23 and Exchange Server 2019 CU14 and CU15. However, anyone using Exchange 2016 or 2019 must have subscribed to the second level of extended security updates (ESU). Microsoft provides further details about the Emergency Mitigation Service on its own website.

Read more after the ad


(dmk)



Unfortunately, this link is no longer valid.

Links to gifted items will be invalid if they are older than 7 days or have been accessed too often.


You need a heise+ package to read this article. Try it now for a week without obligation – without obligation!

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article the anti-iPhone whose photo AI demo embarrasses even Sony the anti-iPhone whose photo AI demo embarrasses even Sony
Next Article Mozilla just revealed how many times Firefox was chosen Mozilla just revealed how many times Firefox was chosen
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Incognito mode for Meta AI: How you can soon have private chats with the AI ​​in Whatsapp
Incognito mode for Meta AI: How you can soon have private chats with the AI ​​in Whatsapp
Gadget
Cisco is cutting almost 4,000 jobs
Cisco is cutting almost 4,000 jobs
News
Mozilla just revealed how many times Firefox was chosen
Mozilla just revealed how many times Firefox was chosen
Gaming
the anti-iPhone whose photo AI demo embarrasses even Sony
the anti-iPhone whose photo AI demo embarrasses even Sony
Mobile

You Might also Like

Mini cameras in public: Criminal law fails when it comes to smart glasses
Software

Mini cameras in public: Criminal law fails when it comes to smart glasses

6 Min Read
Comparison test: Four 700 euro notebooks against the MacBook Neo
Software

Comparison test: Four 700 euro notebooks against the MacBook Neo

3 Min Read
Last Call: AI and data science in the company – from raw data to insights
Software

Last Call: AI and data science in the company – from raw data to insights

5 Min Read
Doctors’ Day: Clear rejection of cash-controlled digitalization in the healthcare system
Software

Doctors’ Day: Clear rejection of cash-controlled digitalization in the healthcare system

7 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?