Microsoft Patches Exchange XSS Zero Day
Microsoft just fixed an actively exploited zero-day in Exchange Server. Attackers used it for XSS against Outlook Web Access users.
The flaw lets unauthenticated attackers run arbitrary JavaScript in victims' browsers. CVE-2025-42897 carried CVSS 8.1 and was actively exploited before the patch.
It affects on-premises Exchange 2016 and 2019. Cloud-hosted Outlook escapes the issue entirely.
Public PoC appeared days after disclosure.
