Microsoft Discloses Exchange Zero-day With No Patch Yet Available
Microsoft has disclosed a zero-day vulnerability that affects Exchange Server 2016, 2019, and Subscription Edition. This vulnerability would give bad actors an opportunity to run arbitrary code remotely on the Exchange server.
Although Microsoft has not issued any patches for this security vulnerability, they suggested two possible mitigations until a solution becomes available.
According to Microsoft, one preferred mitigation strategy is to activate the Exchange Emergency Mitigation (EM) Service, which provides protection for all customers whose EM Service remains enabled by default.
The announcement was made at a time when Microsoft was releasing its May 2026 Patch Tuesday updates, which fixed more than 120 vulnerabilities across applications such as Windows, Office, Azure, SharePoint, and more.
Multiple vulnerabilities addressed this month involve remote code execution and can be exploited via different vectors such as documents, DNS response, and network traffic.
The risk is higher when there’s no patch yet
Jacob Krell,...
Copyright of this story solely belongs to informationsecuritybuzz.com. To see the full text click HERE