Exploited Exchange Server flaw turns OWA inboxes into script launchpads

https://image.theregister.com/246612.jpg?imageId=246612&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Microsoft mitigation may bork inline images, calendar printing while admins wait for a proper patch

Microsoft has confirmed a vulnerability in on-premises Exchange Server that could result in surprise script execution in victims' browsers.

Tracked as CVE-2026-42897, the flaw affects Outlook Web Access (OWA) and can be triggered by a specially crafted email opened in OWA, assuming "certain interaction conditions are met." The prize for attackers is arbitrary JavaScript execution in the mark's browser context.

The advisory describes the flaw as a spoofing vulnerability stemming from cross-site scripting, which will set alarm bells ringing for administrators, and it appears the vulnerability is being exploited. The bug was assigned a CVSS score of 8.1.

Exchange Server 2016, 2019, and the latest version, Exchange Server Subscription Edition (SE), are all affected regardless of their update level. A mitigation has been released via the Exchange Emergency Mitigation (EM) Service.

...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more

https://image.cnbcfm.com/api/v1/image/108306779-1778744604232-gettyimages-2275541264-AFP_B2TG2BT.jpeg?v=1778758999&w=1920&h=1080

Jensen Huang said that Nvidia has “largely conceded” China's AI chip market to Huawei and should “expect nothing” regarding chip sale approvals to China

Sponsor Posts Niantic Spatial: World models need real-world data — Scaniverse is the gateway to spatial services — self-serve and built for AI and robotics. Large-area 3D reconstruction from 360° cameras and precise localization, anywhere machines operate. App Spotlight: Quo for Zoho CRM — App Spotlight brings you hand-picked solutions that enhance your