Close Menu
The Financial News 247The Financial News 247
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
What's On
6 Ways To Photograph The Venus-Jupiter ‘Kiss’ With A Phone Right Now

6 Ways To Photograph The Venus-Jupiter ‘Kiss’ With A Phone Right Now

June 8, 2026
3 Dynasty Fantasy Football Quarterbacks To Trade Away

3 Dynasty Fantasy Football Quarterbacks To Trade Away

June 8, 2026
Microsoft launches incubator for Chinese tech startups — reigniting fears about cozy Beijing ties: ‘Makes no sense’

Microsoft launches incubator for Chinese tech startups — reigniting fears about cozy Beijing ties: ‘Makes no sense’

June 8, 2026
GenAI Is Ready To Change Medicine. America Isn’t Prepared.

GenAI Is Ready To Change Medicine. America Isn’t Prepared.

June 8, 2026
FC Barcelona Target Cucurella Tells Chelsea He Wants To Leave

FC Barcelona Target Cucurella Tells Chelsea He Wants To Leave

June 8, 2026
Facebook X (Twitter) Instagram
The Financial News 247The Financial News 247
Demo
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
The Financial News 247The Financial News 247
Home » Microsoft Confirms Active 0-Day Exploit—Check Emergency Mitigation

Microsoft Confirms Active 0-Day Exploit—Check Emergency Mitigation

By News RoomMay 17, 2026No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Telegram Reddit Email Tumblr
Microsoft Confirms Active 0-Day Exploit—Check Emergency Mitigation
Share
Facebook Twitter LinkedIn Pinterest Email

Updated May 17: This article, originally published May 16, has been updated to include further details on the emergency mitigation process recommended after the CVE-2026-42897 Microsoft Exchange remote code execution zero-day was confirmed by the U.S. Cybersecurity and Infrastructure Security Agency as actively exploited by attackers.

It’s been something of a rough few days for Microsoft Exchange on the security vulnerability front. A zero-day being demonstrated at the Pwn2Own Berlin hacking event, which has been responsibly disclosed and not released into the wild. Definitely already out there, and under active exploitation according to the U.S. Cybersecurity and Infrastructure Security Agency, another Exchange zero-day, confirmed by Microsoft on May 14. CISA added the CVE-2026-42897 vulnerability to its Known Exploited Vulnerabilities Catalog on May 15, urging all organizations to prioritize timely remediation as the attack vector poses a significant risk. Here’s what you need to know.

The Microsoft Exchange CVE-2026-42897 Zero-Day Explained

Microsoft disclosed CVE-2026-42897 on May 14, describing the zero-day as a Microsoft Exchange Server spoofing vulnerability. Technically speaking, the vulnerability occurs when an improper neutralization of input during web page generation, or a cross-site scripting attack if you prefer, enables an attacker to perform spoofing over the network. All it takes to exploit this is to send a maliciously crafted email, which, when opened in Outlook Web Access, can execute arbitrary JavaScript in the context of the browser.

“The disclosure of CVE-2026-42897 is a reminder that on-premises Exchange remains the most targeted piece of real estate in the enterprise stack,” Damon Small, a director at Xcape, Inc., said, adding that “this zero-day allows unauthenticated remote code execution, effectively granting attackers a direct path to the heart of corporate identity and communications.”

Exchange Online is not impacted by the zero-day, but the following on-premises Exchange Server versions are:

  • Exchange Server 2016 (any update level)
  • Exchange Server 2019 (any update level)
  • Exchange Server Subscription Edition (SE) (any update level)

Microsoft has recommended mitigation via the Exchange Emergency Mitigation Service as the patch has already been published through it. “Using EM Service is the best way for your organization to mitigate this vulnerability right away,” Microsoft said; “If you have EM Service currently disabled, we recommend you enable it right away.”

To check the status of the Exchange Emergency Mitigation Service, organizations should run the Exchange Health Checker script provided by Microsoft. “The HTML report will include a section on EEMS check results,” Microsoft has confirmed. This will also verify that your “servers have applied the mitigation for CVE-2026-42897,” Microsoft said, advising that M2.1.x is the relevant mitigation ID to look for.

“Because a formal patch is still pending,” Small wanred, “organizations are forced into a mitigation-only posture, relying on the Emergency Mitigation Service to essentially apply a virtual band-aid to a critical wound.’ The priority, therefore, must be immediate validation that the EM Service is actually functional and applying the necessary URI blocks as, “a single misconfigured server can serve as the beachhead for a full domain compromise.” Small also noted that this incident should be the catalyst to accelerate a move from Exchange Server to Microsoft Exchange Online in the enterprise, or, “at the very least, to isolate these servers behind a zero-trust gateway.”

“Exchange remains one of the most dangerous places for a remote code execution flaw to land,” Jacob Krell, senior director of secure AI solutions and Cybersecurity at Suzu Labs, said, as it “sits close to identity and inside the communication layer most organizations depend on every day.” Krell also warned that “attackers study mitigation guidance the same way defenders do,” meaning that such vulnerabilities can be turned into working exploits “much faster than most organizations can validate exposure.” The message is clear, especially as it has now been confirmed by both CISA and Microsoft itself that attacks are already underway, that checking to ensure the Exchange Emergency Mitigation Service is enabled and the relevant mitigation ID for CVE-2026-42897 applied is not an option; it’s a critical confirmation that your on-premises Microsoft Exchange Server is not at risk of being exploited.

CISA CVE-2026-42897 Exchange Exchange zero-day under active exploitation KEV Catalog Microsoft Exchange Zero-Day Attack Microsoft Security Warning Mitigate Right Now Emergency’ Patch Microsoft Exchange now
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

6 Ways To Photograph The Venus-Jupiter ‘Kiss’ With A Phone Right Now

6 Ways To Photograph The Venus-Jupiter ‘Kiss’ With A Phone Right Now

June 8, 2026
GenAI Is Ready To Change Medicine. America Isn’t Prepared.

GenAI Is Ready To Change Medicine. America Isn’t Prepared.

June 8, 2026
Sentinel Unveils New Riobot RaiOh Toy From ‘Super Robot Wars Alpha 3’

Sentinel Unveils New Riobot RaiOh Toy From ‘Super Robot Wars Alpha 3’

June 8, 2026
Clearing Up The Confusion About What Anthropic Really Said On Globally Pausing The Unrelenting Race Toward AI That Builds AI

Clearing Up The Confusion About What Anthropic Really Said On Globally Pausing The Unrelenting Race Toward AI That Builds AI

June 8, 2026
New Report Claims Apple’s Rumored Foldable Will Only Come In White

New Report Claims Apple’s Rumored Foldable Will Only Come In White

June 8, 2026
How Attenborough’s Film ‘Ocean’ Captured The Scale Of Life At Sea

How Attenborough’s Film ‘Ocean’ Captured The Scale Of Life At Sea

June 8, 2026
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
3 Dynasty Fantasy Football Quarterbacks To Trade Away

3 Dynasty Fantasy Football Quarterbacks To Trade Away

News June 8, 2026

It’s always fun to talk about which quarterbacks are going to take over in dynasty…

Microsoft launches incubator for Chinese tech startups — reigniting fears about cozy Beijing ties: ‘Makes no sense’

Microsoft launches incubator for Chinese tech startups — reigniting fears about cozy Beijing ties: ‘Makes no sense’

June 8, 2026
GenAI Is Ready To Change Medicine. America Isn’t Prepared.

GenAI Is Ready To Change Medicine. America Isn’t Prepared.

June 8, 2026
FC Barcelona Target Cucurella Tells Chelsea He Wants To Leave

FC Barcelona Target Cucurella Tells Chelsea He Wants To Leave

June 8, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks
Sentinel Unveils New Riobot RaiOh Toy From ‘Super Robot Wars Alpha 3’

Sentinel Unveils New Riobot RaiOh Toy From ‘Super Robot Wars Alpha 3’

June 8, 2026
Iran And Israel Trade Strikes Even As Trump Urges Netanyahu Not To Retaliate

Iran And Israel Trade Strikes Even As Trump Urges Netanyahu Not To Retaliate

June 8, 2026
Apple expected to unveil new AI features at last developers conference with CEO Tim Cook

Apple expected to unveil new AI features at last developers conference with CEO Tim Cook

June 8, 2026
Clearing Up The Confusion About What Anthropic Really Said On Globally Pausing The Unrelenting Race Toward AI That Builds AI

Clearing Up The Confusion About What Anthropic Really Said On Globally Pausing The Unrelenting Race Toward AI That Builds AI

June 8, 2026
The Financial News 247
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us
© 2026 The Financial 247. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.