惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Schneier on Security
A
About on SuperTechFans
V
Visual Studio Blog
美团技术团队
雷峰网
雷峰网
J
Java Code Geeks
L
LINUX DO - 最新话题
T
Threatpost
I
Intezer
Simon Willison's Weblog
Simon Willison's Weblog
月光博客
月光博客
博客园 - Franky
The Cloudflare Blog
AWS News Blog
AWS News Blog
T
Tor Project blog
IT之家
IT之家
S
SegmentFault 最新的问题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园_首页
T
The Exploit Database - CXSecurity.com
L
LINUX DO - 热门话题
S
Securelist
V
V2EX
C
CERT Recently Published Vulnerability Notes
T
Threat Research - Cisco Blogs
Attack and Defense Labs
Attack and Defense Labs
人人都是产品经理
人人都是产品经理
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
量子位
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Cyberwarzone
Cyberwarzone
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
大猫的无限游戏
大猫的无限游戏
T
Tenable Blog
爱范儿
爱范儿
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Hacker News: Ask HN
Hacker News: Ask HN
小众软件
小众软件
Spread Privacy
Spread Privacy
S
Security Affairs
NISL@THU
NISL@THU
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
T
The Blog of Author Tim Ferriss
MongoDB | Blog
MongoDB | Blog
AI
AI
Cisco Talos Blog
Cisco Talos Blog
N
Netflix TechBlog - Medium
博客园 - 司徒正美

The Register - On-Prem

Ohio hits pause on datacenter tax breaks draining its coffers Europe told to cool its datacenter boom before water and power run short Kyndryl takes employees' pulse while cutting off circulation for some Outlook has an image problem Microsoft says cu l8r to text message security 'Workforce rebalancing' comes for Kyndryl, and delivery teams are in the firing line MAGA's Mace wants to make power bills great again, calls for datacenter moratorium Datacenters slurping up so much juice they boosted prices 75% in largest US energy market Utah mega datacenter could dump 23 atomic bombs worth of energy per day Rust stalks IBM mainframes, but only in nightly form Iran war hits datacenter building supply chains, upping costs ON CALL: Custom PC worked in the lab, failed on site – and so did the angry client ShinyHunters claims dump puts 119K Vimeo emails in the wild Vodafone dials up full control of VodafoneThree Palantir CEO: 10 percent of world 'professionally hates us' Bad news for OpenClaw stans: Apple’s Mac Mini starts at $799 AWS networking lab tour: Making networking disappear Royal Navy chief backs drones, robot ships Bank of England is gold standard for tech projects, says PAC UK pensions dept shopping for spy-van tech worth up to £2M Microsoft boss tells investors the company is working to 'win back fans' What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Microsoft levels up Azure Local for sovereign clouds Cloudflare: autocrats, wars, and votes caged the net in Q1 ZTE & XLSMART launch Jakarta AI & 5G-A Innovation Center When robots join the race: 5G-A powers a new kind of marathon 5G-A powers a new kind of marathon Oracle plans to power its New Mexico DC with fuel cell farm DCMS to new CDIO: Microsoft migration, overhaul ERP, survive Document sent Boeing Core Scientific accelerates crypto-to-AI pivot Meta seeking energy from space for earth-bound datacenters Golden Dome gets $3.2B of contractors and an AI sprinkle ICO boss Edwards steps back amid workplace investigation DARPA seeks deep-sea drones for autonomous warfare push ZTE Q1 revenue up 6% to RMB 35B; computing mix hits 27% UK govt shells out £550 for Digital ID panel, bans press TUIT & ZTE launch student internship and tech job programs US farms have new steward for their safety nets: Palantir Tesla stakes AI dreams on Intel's unfinished AI chip If malware via monitor cables is a matter of national security, this might be the gadget for you Grafana offers AI assistant for free, warns users not to go mad Right to repair champ Framework punts modular 13in laptop with Core Ultra Series 3 Scotland Yard can keep using live facial recognition on Londoners, say judges Phone-to-satellite use goes into orbit, growing 25% in 8 months FAA grounds Blue Origin's New Glenn as it probes missed satellite delivery 'mishap' AMD's Ryzen 9 9950X3D2 Dual Edition tested: Gratuitous overkill with a price to match Crook claims to leak 'video surveillance footage' of companies Met police trials snoop tech platform in push to cuff more London shoplifters England's school phone ban gets teeth, just in time to bite no one Panasonic creates device-locked QR codes to speed facial biometric capture NASA Inspector fears new spacesuits won’t be ready for Moon landing Trump-branded datacenter project fails to make itself great, again World's blandest man steps down from CEO job to spend more time in tastefully appointed home Chase got a spiff of $77 million to create one job with New York datacenter AI is reshaping Britain's datacenter map away from London HP's remote desktop push retreats as Anyware heads for end of life 'Invisible mouse' made a mess of PC rebuild Indonesia’s game rating system paused amid claims it leaked developer creds and glimpses of major new titles Intel eases reliance on TSMC with 'Merica-made Core Series 3 processors Attention data hoarders: Alexa loses its Plex appeal as voice feature gets canned Locked-out iPhone user tells The Reg that Apple is scrambling to fix character flaw passcode bug Capita won disastrous UK pensions gig after acing performance checks Maine to pause big bit barns as local opposition spreads Iran has something America can only dream of: cheap broadband Guide to GPU virtualization: passthrough, vGPU, and MIG Brussels tells Google to hand rivals its search crown jewels as privacy row brews Cops hand Motorola £25M to keep 2000-era radios alive QUIC will soon be as important as TCP – but it's vastly different Networks not ready for the challenges of AI traffic US states can't account for datacenter tax breaks. Literally UK told its Big Tech habit is now a national security risk The only technology that died more times than VR is AI, and that seems to have worked out Oracle taps Bloom for fuel cells to support datacenter binge Amazon pays $11.5B to satisfy satellite-envy while cowering in Musk's shadow Microsoft raises UK Surface prices as RAM crisis reaches the checkout UK state bank considers lengthening disastrous IT program Japan going back to the future by reviving its chip industry FAA seeking gamers to fill air traffic control ranks Veterans Affairs software licensing under fire in GAO report NHS pays £46K to prep next Microsoft licensing round France’s digital agency dumping Windows desktops for Linux IT manager approved lunch downtime, but made a meal of it China wants AI to prepare school lessons and mark homework Apple update turns Czech mate for locked-out iPhone user Hungary officials used weak passwords exposed in breach dump Amazon rejects AWS climate disclosure proposal Tiny violins as Amazon execs face pay packet pinch John Deere agrees $99m right-to-repair settlement Iran war piles more pain on already battered PC market AWS put a file system on S3; I stress-tested it UK to spend £15M on AI mapping in knife crime crackdown Rebrand automation as 'zero-token architecture' to master AI Supply chain challenges risk delaying Nvidia's Rubin GPUs Amazon thanks loyal Kindle devotees by bricking their kit DXC lands Metropolitan Police contract worth up to £1B NHS Scotland-linked domains push pr0n and illegal streams How to navigate the storage crunch in the AI era Supermicro launches probe after staff charged with China export violations
Exploited Exchange Server flaw turns OWA inboxes into script launchpads
Richard Speed Richard Speed · 2026-05-15 · via The Register - On-Prem

On-Prem

Microsoft mitigation may bork inline images, calendar printing while admins wait for a proper patch

Microsoft has confirmed a vulnerability in on-premises Exchange Server that could result in surprise script execution in victims' browsers.

Tracked as CVE-2026-42897, the flaw affects Outlook Web Access (OWA) and can be triggered by a specially crafted email opened in OWA, assuming "certain interaction conditions are met." The prize for attackers is arbitrary JavaScript execution in the mark's browser context.

The advisory describes the flaw as a spoofing vulnerability stemming from cross-site scripting, which will set alarm bells ringing for administrators, and it appears the vulnerability is being exploited. The bug was assigned a CVSS score of 8.1.

Exchange Server 2016, 2019, and the latest version, Exchange Server Subscription Edition (SE), are all affected regardless of their update level. A mitigation has been released via the Exchange Emergency Mitigation (EM) Service. 

However, Microsoft warned the mitigation might break other things – inline images might stop working in the recipient's OWA reading pane (use attachments instead) and the OWA Print Calendar functionality might not work (use a screenshot or the Outlook Desktop client).

Finally, OWA Light might not work properly. Microsoft deprecated this in 2024, so affected users should consider an upgrade.

The mitigation can also be applied manually in scenarios where customers are not using the EM service. These might be disconnected or air-gapped environments – exactly the sort of environments where on-premises Exchange tends to linger.

Microsoft is working on a full security update, although only the Exchange SE version will be publicly available. Exchange 2016 and 2019 customers will receive it only if enrolled in Period 2 of the Exchange Server Extended Security Updates (ESU) program. The second period of Exchange Server ESU kicked off this month, with Microsoft sternly warning that there would be no extensions past its end. The vulnerability does not affect Exchange Online.

Microsoft has not given any details on how the exploit works, nor how widely it is being exploited. ®