By Davey Winder
Publication Date: 2026-05-17 11:04:00
Microsoft confirms Exchange zero-day, CISA warns it’s under active exploitation.
getty
Updated May 17: This article, originally published May 16, has been updated to include further details on the emergency mitigation process recommended after the CVE-2026-42897 Microsoft Exchange remote code execution zero-day was confirmed by the U.S. Cybersecurity and Infrastructure Security Agency as actively exploited by attackers.
It’s been something of a rough few days for Microsoft Exchange on the security vulnerability front. A zero-day being demonstrated at the Pwn2Own Berlin hacking event, which has been responsibly disclosed and not released into the wild. Definitely already out there, and under active exploitation according to the U.S. Cybersecurity and Infrastructure Security Agency, another Exchange zero-day, confirmed by Microsoft on May 14. CISA added the CVE-2026-42897 vulnerability to its Known Exploited Vulnerabilities Catalog on May 15, urging all organizations to prioritize…



