Switch language한국어
Back to the list

Microsoft Confirms Active 0-Day Exploit—Check Emergency Mitigation Now

TL;DR AI

Key summary

2 min read
  1. Microsoft confirmed CVE-2026-42897, a spoofing zero-day in on-premises Exchange Server, is being actively exploited.

  2. CISA added the flaw to its exploited-vulnerabilities list after detecting real-world attacks.

  3. Microsoft is urging organizations to enable Exchange Emergency Mitigation Service protections immediately and verify status with Health Checker.

  4. The issue puts email, identity, and corporate communications at immediate risk until a full patch is available.

Read the original