Microsoft Confirms Active 0-Day Exploit—Check Emergency Mitigation Now

TL;DR AI
2 min readKey summary
Microsoft confirmed CVE-2026-42897, a spoofing zero-day in on-premises Exchange Server, is being actively exploited.
CISA added the flaw to its exploited-vulnerabilities list after detecting real-world attacks.
Microsoft is urging organizations to enable Exchange Emergency Mitigation Service protections immediately and verify status with Health Checker.
The issue puts email, identity, and corporate communications at immediate risk until a full patch is available.



