Microsoft Exchange Active 0-Day Exploit—Enable Emergency Mitigation Now

Microsoft Exchange Active 0-Day Exploit—Enable Emergency Mitigation Now

By Davey Winder
Publication Date: 2026-05-16 16:47:00

It’s been something of a rough few days for Microsoft Exchange on the security vulnerability front. A zero-day being demonstrated at the Pwn2Own Berlin hacking event, which has been responsibly disclosed and not released into the wild. Definitely already out there, and under active exploitation according to the U.S. Cybersecurity and Infrastructure Security Agency, another Exchange zero-day, confirmed by Microsoft on May 14. CISA added the CVE-2026-42897 vulnerability to its Known Exploited Vulnerabilities Catalog on May 15, urging all organizations to prioritize timely remediation as the attack vector poses a significant risk. Here’s what you need to know.

ForbesMicrosoft Windows Alert—Angry Hacker Drops 2 New Zero-Day Exploits

The Microsoft Exchange CVE-2026-42897 Zero-Day Explained

Microsoft disclosed CVE-2026-42897 on May 14, describing the zero-day as a Microsoft Exchange…