Story perspectives
US Exploited Exchange Zero-Day Prompts Urgent Microsoft Mitigation
5/17/2026
1 of 4
Microsoft Confirms Exploit
- Microsoft confirmed the Exchange Server zero-day CVE-2026-42897 is being exploited in the United States.
- The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-42897 to its Exploited Vulnerabilities Catalog on May 15.
- Microsoft urged customers to enable the Emergency Mitigation Service, use the on-premises tool, and apply the upcoming patch for Exchange 2016, 2019 and Subscription Edition.
- Security experts recommended moving to Exchange Online or isolating on-premises servers behind a zero-trust gateway.
1 / 4
