CISA Warns of Actively Exploited Microsoft Exchange Server XSS Flaw — Patch by May 29
CISA has added CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange Server’s Outlook Web Access, to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. Federal agencies face a May 29 remediation deadline, and all organizations using on-premises Exchange are urged to patch immediately to prevent session hijacking and credential theft.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.