Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Zero Day - Microsoft discloses Exchange zero-day with no patch yet available
Zero Day Application Security Latest News News & Analysis Security Threats and Vulnerabilities

Microsoft discloses Exchange zero-day with no patch yet available

Kirsten DoyleBy Kirsten DoyleMay 18, 20263 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Microsoft Exchange zero-day
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Microsoft has disclosed a zero-day vulnerability that affects Exchange Server 2016, 2019, and Subscription Edition. This vulnerability would give bad actors an opportunity to run arbitrary code remotely on the Exchange server. 

Although Microsoft has not issued any patches for this security vulnerability, they suggested two possible mitigations until a solution becomes available.  

According to Microsoft, one preferred mitigation strategy is to activate the Exchange Emergency Mitigation (EM) Service, which provides protection for all customers whose EM Service remains enabled by default.    

The announcement was made at a time when Microsoft was releasing its May 2026 Patch Tuesday updates, which fixed more than 120 vulnerabilities across applications such as Windows, Office, Azure, SharePoint, and more.  

Multiple vulnerabilities addressed this month involve remote code execution and can be exploited via different vectors such as documents, DNS response, and network traffic. 

The risk is higher when there’s no patch yet 

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, at Suzu Labs, says: “Exchange remains one of the most dangerous places for a remote code execution flaw to land. It sits close to identity and inside the communication layer most organizations depend on every day.” 
   
He says the risk is higher when there is no patch yet. Attackers study mitigation guidance the same way defenders do. AI only compresses that timeline. Public details can now be turned into working exploits much faster than most organizations can validate exposure.  
   
“Microsoft’s Emergency Mitigation Service gives defenders a bridge, but that bridge still has to be verified. Exposure management now matters as much as patch management. Organizations need to know where Exchange is reachable and whether the mitigation actually landed.”  

On-premises Exchange remains the most targeted pieces of real estate 

Damon Small, Board of Directors, at Xcape Inc, adds: “The disclosure of CVE-2026-42897 is a reminder that on-premises Exchange remains the most targeted piece of real estate in the enterprise stack. This zero-day allows unauthenticated remote code execution, effectively granting attackers a direct path to the heart of corporate identity and communications. Because a formal patch is still pending, organizations are forced into a mitigation-only posture, relying on the Emergency Mitigation Service to essentially apply a virtual band-aid to a critical wound.  

“For security leaders, this incident should be the final catalyst to accelerate the move to Exchange Online or, at the very least, to isolate these servers behind a zero-trust gateway. The priority must be immediate validation that the EM Service is actually functional and applying the necessary URI blocks, as a single misconfigured server can serve as the beachhead for a full domain compromise.  In sum, most companies’ core competency is not maintaining IT infrastructure and should outsource those responsibilities.  

 He says companies should heed these takeaways:  

  • “Trust the Service, not the Server: If your Exchange Emergency Mitigation Service is disabled, you are currently defenseless; manual URI blocks are the only alternative until a formal binary patch is released.  
  • “Identical Patterns: This flaw echoes ProxyLogon and ProxyShell, demonstrating that the architectural complexity of on-premises Exchange continues to provide a fertile ground for unauthenticated RCE.  
  • “The Hybrid Trap: Organizations in hybrid mode must ensure their on-premises footprint does not become the weakest link that compromises their cloud-based identity and mailboxes.  

“Microsoft’s “Emergency Mitigation Service” is a polite way of saying your server is on life support, and the attackers are the ones currently holding the remote control.”  

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw
  • Kirsten Doyle
    CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet
  • Kirsten Doyle
    Threat Actors Deploy Tiflux RMM for Persistent Remote Access

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

WhatsApp Reveals Zero-Day Exploited in Targeted Apple Attacks

September 3, 20253 Mins Read

Windows Shortcut Zero-Day Under Active Attack

March 21, 20254 Mins Read

Broadcom Warns VMware Users of Critical Zero-Day Exploits

March 7, 20253 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}