Hackers can take over your work email by sending you a single message. You do not have to click anything. Just opening the email is enough. The bug is in Microsoft Exchange, the email server that runs at most schools, county governments, and businesses that still host their own mail. Microsoft confirmed the problem on May 14, 2026.
The bug has a tracking number, CVE-2026-42897, which is just an ID code given to a security flaw so everyone can refer to the same one. CISA, the US Cybersecurity and Infrastructure Security Agency, added it to their list of bugs that attackers are already using, and several outside trackers say the same thing. So this is not a maybe. Real attackers are hitting it right now. Update your server today.
The Hacker News Prem Microsoft Exchange Server CVE Exploited
What the bug does
Attackers hide small bits of code inside an email. When Outlook opens the message, the Exchange server is supposed to clean those bits out but misses some. Your browser then runs the attacker's code as if you wrote it yourself.
That code has the same access to your mailbox that you do. The attacker can read every email you have, forward sensitive threads, trigger password resets on services tied to your work address, and take over even more if you happen to be an admin. Security people call this kind of flaw remote code execution, which just means an outsider gets to run their own commands on your server from across the internet. No login needed. No warning. Worst case, one rigged email lands in an inbox and the whole mail system is theirs.
The fix
Microsoft released two things on the same day.
- The May 2026 Exchange update. This is a regular software fix, the kind that closes the hole in the program.
- A blocking rule that tells your browser to ignore code coming in through email. It installs automatically on servers signed up for Microsoft's Exchange Emergency Mitigation Service.
Health Checker lies about the fix
The blocking rule installs in one place. Microsoft's own Exchange Health Checker tool looks for it in a different place. The result is that Health Checker reports "not protected" on servers that are actually protected. A community researcher posted this on GitHub before Microsoft confirmed it.
Check the protection rule yourself by looking at the outbound rules in IIS, the Windows web server software that runs Exchange. Do not trust Health Checker for this one.
What to do tonight
- Install the May 2026 Exchange update on every server you run yourself, meaning the ones in your own building rather than rented from the cloud.
- Check the protection rule yourself in IIS, do not trust the automated tool.
- Check your webmail access logs from the past two weeks. Look for strange read activity on executive mailboxes.
- If you are still on Exchange 2016 or 2019, plan the move to Exchange Server SE.
Why this keeps happening
Exchange that companies run on their own servers, instead of in the cloud, has been one of the most attacked products of the past decade. ProxyLogon and ProxyShell in 2021 hit tens of thousands of servers and were the work of Hafnium, a Chinese government hacking group. Now this. All three problems were in the part of Exchange that handles webmail.
The number of these servers has barely shrunk because moving is expensive, and some rules about keeping data in-house still push companies to run their own mail. Schools, local governments, and hospitals are the ones stuck running it, and they are often the slowest to apply fixes. That is exactly why attackers keep aiming here. If you can move to Exchange Online, the cloud version, do it. If you cannot, expect a steady cycle of emergency fixes like this one.
Infosecurity Magazine AI Raises Bar Vulnerability Awareness Secure






