Return to Global Matrix
CLASSIFIED: EYES ONLY

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

TELEMETRY SUMMARY DECRYPTION

SITREP: Microsoft has reported a new security vulnerability, CVE-2026-42897, affecting on-premise versions of Exchange Server, which is currently being actively exploited. The vulnerability is characterized as a spoofing bug linked to a cross-site scripting flaw and has a CVSS score of 8.1. TACTICAL ASSESSMENT: The active exploitation of this vulnerability poses significant risks to organizations using on-premise Exchange Servers, potentially leading to unauthorized access and data breaches. This incident highlights the ongoing challenges in cybersecurity, particularly regarding legacy systems. PROJECTED VECTORS: Future attacks may increase as threat actors leverage this vulnerability to target organizations still using affected Exchange Server versions.

SAT-COM 4LAT: 45.192LON: 34.021UTC: 2026-05-15

Event Telemetry

STATUS IDENTIFIERNORMAL TRAFFIC
ORIGIN DESKCYBER
ACQUISITION TIME05/1508:11 ZULU
AUTHORSYSTEM.AUTO[992]