惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
A
About on SuperTechFans
量子位
B
Blog RSS Feed
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园_首页
MongoDB | Blog
MongoDB | Blog
小众软件
小众软件
Blog — PlanetScale
Blog — PlanetScale
Microsoft Azure Blog
Microsoft Azure Blog
V
V2EX
Google DeepMind News
Google DeepMind News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
G
Google Developers Blog
U
Unit 42
D
DataBreaches.Net
博客园 - Franky
D
Docker
宝玉的分享
宝玉的分享
Y
Y Combinator Blog
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Hugging Face - Blog
Hugging Face - Blog

CSO Online

New malware turns Linux systems into P2P attack networks Poisoned truth: The quiet security threat inside enterprise AI Train like you fight: Why cyber operations teams need no-notice drills Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS
Exchange Server zero-day vulnerability can be triggered b...
2026-05-16 · via CSO Online

A newly discovered zero-day vulnerability in Microsoft Exchange Server has experts declaring an emergency and urging CSOs to think about the need to abandon on-premises email solutions.

“Because it’s already being exploited in the wild, this isn’t a ‘patch next week situation; it’s a ‘mitigate right now’ emergency,” warned Rob Enderle of the Enderle Group.

“This is another reminder to find a trusted cloud provider for e-mail,” added Johannes Ullrich, dean of research at the SANS Institute. “On-premises Exchange is becoming a legacy product, and while some organizations need it for internal and outbound email, its attack surface should be minimized by reducing its exposure to external email.”

Ullrich was commenting on an alert from Microsoft this week about a cross-site scripting vulnerability affecting Exchange Outlook Web Access (OWA) that could be exploited merely by sending a specially crafted email to a user.  If the user opens the message in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

Avoiding cross-site scripting problems in webmail systems like Outlook Web Access is hard, Ullrich admitted. A webmail system must include HTML email received from users within the application’s HTML without confusing the two. Techniques like sandboxed iFrames can help, but need to be applied carefully.

At the same time, he said, cross-site scripting flaws in webmail can usually be used to read the content of an email, and in some cases even to send an email.

“Luckily,” he added, “many organizations have moved away from on-premises Exchange and Outlook Web Access.”

“I’m guessing this is bad,” said Kellman Meghu,” CTO of DeepCove Cybersecurity, “but so is running an onsite Exchange Server in general.”

Affected by the vulnerability (CVE-2026-42897) are Exchange Server 2016, 2019, and Server Subscription Edition (SE), regardless of their update levels.

The cloud service, Exchange Online, is unaffected.

Mitigation

Microsoft is still working on a security patch. In the meantime, Exchange administrators should know that if the Exchange EM Service is enabled on their servers – and it should be; since its release in September 2021 it has been enabled by default – then Microsoft’s automatic mitigation for this vulnerability has already been published for affected versions of Exchange.

If EM Service for whatever reason has been disabled, it should be enabled immediately. Note, however, that EM Service won’t be able to check for new mitigations if the server is running an Exchange Server version older than March 2023.

Those who can’t use the EM Server, because, for example, they are disconnected or have air-gapped environments, should download the latest version of the Exchange on-premises Mitigation Tool (EOMT) and apply the mitigation on a per server base, or on all servers at once by running the script via an elevated Exchange Management Shell.

Known issues with mitigation tactics

However, admins should note there are known issues once the mitigation is applied either manually or automatically through the EM Service.

OWA Print Calendar functionality might not work. As a workaround, copy the data or screenshot the calendar you want to print, or use Outlook Desktop client.

Inline images might not display correctly in the recipient’s OWA reading pane. As a workaround, send images as email attachments or use Outlook Desktop client.

OWA light (OWA URL ending in /?layout=light) does not work properly. Note that this feature was deprecated several years ago and is not intended for regular production use.

Admins may get a message saying “Mitigation invalid for this Exchange version.” in mitigation details. This issue is cosmetic and the mitigation does apply successfully if the status is shown as “Applied”. Microsoft is investigating how to address this glitch.

Updates coming ‘in the future’

A Microsoft spokesperson was asked when the security update would be released. We were referred to the company’s statement. 

In its warning, Microsoft says security updates for impacted versions of Exchange Server will come “in the future.” They will be for Exchange SE RTM, Exchange 2016 CU23, and Exchange Server 2019 CU14 and CU15. Those running older CU versions are urged to update now.

An Exchange SE update will be released as a publicly available security update. Exchange 2016 and 2019 updates will be released only to customers who are enrolled in the Period 2 Exchange Server ESU program. Period 1-only ESU customers will not receive this update, as that program ended last month.

 Enderle said the fact that Microsoft issued an interim fix that breaks features like calendar printing and inline images is “a clear sign of how desperate they are to stop the bleeding.

“CSOs need to move past the ‘wait and see’ approach and treat this as a litmus test for their security automation,” he said. “If your team has the Exchange Emergency Mitigation (EM) Service enabled, you should already be protected, but you need to verify that ‘Mitigation M2’ is actually active across your entire inventory. If you’re running air-gapped or have the EM service disabled, you’re sitting ducks until you manually run the EOMT script.”

This is another “massive nudge” from Redmond to shift from on-premises email, Enderle added. “If you aren’t already planning your exit from on-site Exchange, your risk profile is only going to keep climbing as these zero days become the new normal. This does showcase that Azure, and web services in general, are where the industry, and particularly Microsoft, is pushing IT to go, whether they want to or not.”

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.