Tag: Microsoft Exchange Server

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
News

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

A new security flaw affecting on-premise Exchange Server versions has been revealed by Microsoft, which claims it has been actively exploited in the wild. The vulnerability has been identified as a spoofing fault resulting from a cross-site scripting flaw and is tagged as CVE-2026-42897 (CVSS score: 8.1). The problem was identified and reported by an unidentified researcher. According to a Thursday advisory from the tech giant, improper neutralization of input during web page creation (often known as "cross-site scripting") in Microsoft Exchange Server enables an unauthorized attacker to perform spoofing over a network. An attacker could weaponize the vulnerability by sending a user a crafted email that, when viewed in Outlook Web Access and subject to additional "certain interac...
MS Exchange Server Flaws Exploited to Deploy Keylogger in Targeted Attacks
News

MS Exchange Server Flaws Exploited to Deploy Keylogger in Targeted Attacks

A known security vulnerability in Microsoft Exchange Server is being used by an unidentified threat actor to launch keylogger malware attacks against organizations in the Middle East and Africa. Positive Technologies, a Russian cybersecurity company, reported that it has identified more than 30 victims, including banks, government organizations, IT firms, and educational institutions. The year 2021 was the first compromise in history. The business stated in a report released last week that "this keylogger was collecting account credentials into a file accessible via a special path from the internet." Russia, the United Arab Emirates, Kuwait, Oman, Niger, Nigeria, Ethiopia, Mauritius, Jordan, and Lebanon are among the nations that the intrusion set targets read more MS Exchange Se...