Microsoft Warns of Active Exploitation Targeting On-Premises Exchange Servers Through Malicious Emails post, mei 15, 2026mei 18, 2026 Security researchers and enterprise defenders are scrambling to respond after Microsoft disclosed that attackers are actively exploiting a newly discovered vulnerability in on-premises Microsoft Exchange Server deployments, potentially allowing threat actors to execute malicious scripts through specially crafted emails. The vulnerability, identified as CVE-2026-42897, carries a CVSS severity score of 8.1 and affects multiple versions of Microsoft Exchange Server used inside corporate environments worldwide. According to Microsoft, the flaw stems from improper neutralization of user-supplied input during web page generation — a class of weakness more commonly associated with cross-site scripting (XSS) vulnerabilities. (4) Microsoft Warns of Active Exploitation Targeting On-Premises Exchange Servers Through Malicious Emails | LinkedIn: Microsoft Warns of Active Exploitation Targeting On-Premises Exchange Servers Through Malicious Emails vulnerability 2026