Microsoft patches Exchange flaw already exploited in attacks
Microsoft has released the June 2026 Exchange Server security updates, addressing CVE-2026-42897, an Exchange Server spoofing and cross-site scripting vulnerability previously reported as exploited in the wild. The flaw affects Exchange Server 2016, Exchange Server 2019 and Exchange Server Subscription Edition, and can be triggered by a specially crafted email opened in Outlook Web Access under certain interaction conditions. Microsoft also recommends keeping the earlier mitigation in place after installing the update, for additional protection.
What this means for your organisation
For organisations still running Exchange on premises, this is a vulnerability exploited by the user doing something entirely routine: opening an email in the browser. The mail server typically holds both business correspondence and material that triggers notification duties under data protection law if it goes astray. Because the flaw was exploited before the fix arrived, patching alone is not enough; you also need to establish whether something has already happened.
Berigo recommends
- Install the June update on every Exchange server, including those retained only for hybrid coexistence.
- Keep the earlier mitigation enabled after updating, as Microsoft advises.
- Review Exchange logs for suspicious activity covering the period before the update was installed.
- Put a plan in place to retire on-premises Exchange servers that remain only for historical reasons.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch