
Microsoft has revealed a new threat affecting Microsoft Exchange Servers, a zero-day vulnerability that is reportedly being exploited by hackers. This was demonstrated at the Pwn2Own Berlin hacking event on 14 May, showing how an attacker could carry out the threat through a specially crafted email.
The security flaw was identified as CVE-2026-42897. It is a spoofing vulnerability that affects fully updated versions of Microsoft Exchange 2016, Exchange Server 2019 and Exchange Server Subscription Edition (SE).