CT
CyberTimes
HomeThreat WatchCVE-2026-42897
Vulnerability Advisory

CVE-2026-42897

Hackers are using a new Microsoft Exchange email attack to hijack office accounts in India. Learn how this hidden virus works and how to protect your company data.

Severity
high
CVSS Score
0 / 10
Fix Status
Patch available
Published
May 15, 2026

Key Facts

  • What is it? Hackers are sending specially crafted "poisoned" emails. If you open one in your browser-based work email, it runs a hidden script to hijack your account.
  • How does it affect YOU? Scammers can read your private work emails, steal sensitive documents, and send fake messages to your colleagues or vendors asking for money.
  • What should YOU do? Do not open suspicious emails at work, immediately alert your IT department so they can apply Microsoft's emergency patch, and report any financial fraud to the 1930 helpline.

Full Analysis

How the Microsoft Exchange Email Attack Works and What To Do

Deep-dive: technical breakdown, real-world impact, complete remediation steps, and expert context.

Read the full report →
← All threat reportsAll articles