Microsoft Exchange users are urged to mitigate a zero-day vulnerability that CISA has confirmed is under active exploitation.
Critical-severity CVE-2026-42897 could lead to remote code execution, and hackers are already taking advantage.