Web TippsAdd co-presenters in Google Meet with one click(01.09.2026 um 17:28 Uhr)
Web TippsGoogle Workspace Weekly Recap - September 4, 2026(04.09.2026 um 21:08 Uhr)
Web TippsAdd co-presenters in Google Meet with one click(01.09.2026 um 17:28 Uhr)
Web TippsGoogle Workspace Weekly Recap - September 4, 2026(04.09.2026 um 21:08 Uhr)

4 🕛 kürzlich 5 Min Lesezeit CVE-2026-42897
0

Exchange Server zero-day vulnerability can be triggered by opening a malicious email

Cyber Threat & Vulnerability Dossier CVSS 5.8 MEDIUM (Heuristik) EPSS 96.1%
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
🛡️ Client-Manipulation (XSS) / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-79: Cross-Site Scripting
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
Im CVE-Radar öffnen
↗ Quelle (csoonline.com)
🔬 IoC Intelligence (1 Indikatoren erkannt)
CVE-2026-42897
🗣️ Stimme:
📑 Inhaltsübersicht








A newly discovered zero-day vulnerability in Microsoft Exchange Server has experts declaring an emergency and urging CSOs to think about the need to abandon on-premises email solutions.





“Because it’s already being exploited in the wild, this isn’t a ‘patch next week situation; it’s a ‘mitigate right now’ emergency,” warned , dean of research at the SANS Institute. “On-premises Exchange is becoming a legacy product, and while some organizations need it for internal and outbound email, its attack surface should be minimized by reducing its exposure to external email.”





Ullrich,” CTO of DeepCove Cybersecurity, “but so is running an onsite Exchange Server in general.”





Affected by the vulnerability ( and apply the mitigation on a per server base, or on all servers at once by running the script via an elevated Exchange Management Shell.





Known issues with mitigation tactics





However, admins should note there are known issues once the mitigation is applied either manually or automatically through the EM Service.





OWA Print Calendar functionality might not work. As a workaround, copy the data or screenshot the calendar you want to print, or use Outlook Desktop client.





Inline images might not display correctly in the recipient’s OWA reading pane. As a workaround, send images as email attachments or use Outlook Desktop client.





OWA light (OWA URL ending in /?layout=light) does not work properly. Note that this feature was . Period 1-only ESU customers will not receive this update, as that program ended last month.





 Enderle said the fact that Microsoft issued an interim fix that breaks features like calendar printing and inline images is “a clear sign of how desperate they are to stop the bleeding.





“CSOs need to move past the ‘wait and see’ approach and treat this as a litmus test for their security automation,” he said. “If your team has the Exchange Emergency Mitigation (EM) Service enabled, you should already be protected, but you need to verify that ‘Mitigation M2’ is actually active across your entire inventory. If you’re running air-gapped or have the EM service disabled, you’re sitting ducks until you manually run the EOMT script.”





This is another “massive nudge” from Redmond to shift from on-premises email, Enderle added. “If you aren’t already planning your exit from on-site Exchange, your risk profile is only going to keep climbing as these zero days become the new normal. This does showcase that Azure, and web services in general, are where the industry, and particularly Microsoft, is pushing IT to go, whether they want to or not.”


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf csoonline.com.
↗ Original-Artikel auf csoonline.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 41%
🟡 In Evaluierung 28%
🟢 Keine Auswirkung 17%
Spannende Innovation 14%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
6 Quellen
Add co-presenters in Google Meet with one click
4 Quellen
IFA 2026: Acer Announces New Laptops, Gaming Handhelds, and More
2 Quellen
Custom instructions for Gemini in Workspace now available in more apps
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Exchange Server zero-day vulnerability can be triggered by opening a malicious email

Thematisch verwandte Begriffe: Exchange, Server, zeroday, vulnerability · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...