Microsoft Exchange Zero-Day Under Attack, No Patch Available
Source: Dark Reading · Category: Ransomware & Breach
Microsoft Exchange zero-day (CVE-2026-42897) exploits XSS vulnerability in Outlook Web Access; no patch currently available. Law firms heavily dependent on Exchange must implement immediate OWA access controls and monitor for exploitation until patch release; this is a widely-used platform affecting nearly all firms.