Skip to content
The Nexus
DossierENTITY

Outlook Web Access

Coverage of Outlook Web Access in the Nexus archive.

Earliest in view: May 15 · 11:51 UTCMost recent: Jun 10 · 13:44 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJun 10 · 13:44 UTCBLEEPING COMPUTER
    Microsoft patches Exchange Server zero-day exploited in attacks

    Microsoft has patched a zero-day vulnerability in Exchange Server that allows threat actors to execute arbitrary JavaScript code through cross-site scripting (XSS) attacks targeting Outlook Web Access users. The vulnerability is actively exploited, prompting the release of a security update.

  • SECURITYMay 15 · 11:51 UTCTHE REGISTER
    Exploited Exchange Server flaw turns OWA inboxes into script launchpads

    Microsoft confirmed a vulnerability in on-premises Exchange Server that could result in script execution in victims' browsers, affecting Outlook Web Access and tracked as CVE-2026-42897. The flaw can be triggered by a specially crafted email and has a CVSS score of 8.1. A mitigation has been released via the Exchange Emergency Mitigation Service.

Outlook Web Access · Dossier · The Nexus