Microsoft Confirms Active 0-Day Exploit—Check Emergency Mitigation

TL;DR AI
2 min readKey summary
Microsoft says Exchange Server CVE-2026-42897 is being actively exploited as a zero-day, prompting urgent action from defenders.
CISA has added the flaw to its Known Exploited Vulnerabilities catalog after confirming real-world attacks.
The bug could allow remote code execution or user spoofing on on-premises Exchange servers, risking email and network compromise.
Microsoft advises organizations to enable the Exchange Emergency Mitigation Service and run the Health Checker script to verify protections while waiting for a patch.



