Cybersecurity — 2026-05-16

Microsoft Confirms Active Exploitation of Exchange Server Zero-Day as Pwn2Own Researchers Amplify Risk

BLUFActive exploitation of an unpatched Exchange zero-day demands immediate mitigation regardless of who is behind it, though attribution to a state-sponsored actor by end of August 2026 remains genuinely uncertain absent any disclosed campaign indicators.

The Pwn2Own Berlin 2026 demonstration by Orange Tsai of DEVCORE Research Team was a separate, distinct three-bug chain achieving full remote code execution with SYSTEM privileges on Exchange, not a demonstration of CVE-2026-42897 specifically, earning $200,000; per contest rules, technical details remain embargoed for 90 days. Microsoft has not attributed the in-the-wild exploitation to any specific threat actor and has disclosed no details on targets, campaign scale, or confirmed attack success. Connected Exchange servers receive automatic mitigation via the Exchange Emergency Mitigation (EM) Service; air-gapped environments must manually run the Exchange On-premises Mitigation Tool (EOMT). The permanent patch is planned for Exchange SE RTM, Exchange 2016 CU23, and Exchange 2019 CU14 and CU15.

Analysis
With no permanent patch available and exploitation already active, every internet-exposed Exchange OWA deployment is at immediate risk; the Pwn2Own Berlin SYSTEM-level chain will extend that exposure once its embargo lifts around mid-August. Per a single Microsoft vendor advisory with no independent corroboration, state-sponsored attribution by end of August 2026 is genuinely uncertain: no actor named, no campaign indicators or targeted sectors disclosed. The activity may instead reflect opportunistic probing constrained by the user-interaction requirement. Confirmed attribution would trigger CISA KEV listing and mandatory federal patching timelines; absent that signal, administrators manage this as a standard critical unpatched vulnerability.
4 sources
  1. Unpatched Microsoft Exchange Server vulnerability exploited - Help Net Security
  2. Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 - Microsoft Tech Community (Exchange Team Blog)
  3. Microsoft warns of Exchange zero-day flaw exploited in attacks - BleepingComputer
  4. Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild - SecurityWeek

View in full brief →

UNCLASSIFIED // OPEN SOURCE