Do you use Microsoft Exchange? Hackers are actively exploiting a new zero-day flaw

A person using a laptop with a warning message appearing on screen
(Image credit: Shutterstock)

A newly discovered zero-day vulnerability in Microsoft Exchange Server has experts sounding the alarm. On Thursday, Microsoft announced mitigations for a high-security Exchange Server vulnerability that's being actively exploited by hackers. All an attacker needs to do is send a specially crafted email that, when opened through Outlook Web Access, can execute arbitrary code within the user's browser.

Microsoft's called this security flaw (tracked as CVE-2026-42897) a spoofing vulnerability affecting fully updated versions of Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE).

Latest Videos From

Google News

Follow Tom's Guide on Google News and add us as a preferred source to get our up-to-date news, analysis, and reviews in your feeds. Subscribe to Tom's Guide on YouTube and follow us on TikTok. Finally, you can visit our dedicated Tom's Guide Savings Squad hub for expert help on getting the best products for less.


More from Tom's Guide

Alyse Stanley
News Editor

Alyse Stanley is a news editor at Tom’s Guide, overseeing weekend coverage and writing about the latest in tech, gaming, and entertainment. Before Tom’s Guide, Alyse worked as an editor for the Washington Post’s sunsetted video game section, Launcher. She previously led Gizmodo’s weekend news desk and has written game reviews and features for outlets like Polygon, Unwinnable, and Rock, Paper, Shotgun. She’s a big fan of horror movies, cartoons, and roller skating. She's also a puzzle fan and can often be found contributing to the NYT Connections coverage on Tom's Guide

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.