Microsoft Exchange Zero-Day Flaws Actively Exploited in Ongoing Attacks
Threat actors actively exploit newly discovered zero-day vulnerabilities in Microsoft Exchange servers, posing significant risks to unpatched organizations. Security researchers urge immediate mitigation to prevent unauthorized access and data theft.
Microsoft confirms that cybercriminals actively exploit two new zero-day vulnerabilities in Microsoft Exchange servers. These critical flaws allow attackers to bypass authentication and execute remote code, giving them unauthorized access to sensitive enterprise email environments without requiring any user interaction.
Security researchers at Arctic Wolf observe these attacks occurring in the wild, meaning real-world threat actors use them against active targets rather than just theoretical proofs of concept. The exploitation focuses on legacy on-premises Exchange servers, which remain highly valuable targets for hackers seeking to steal corporate data or establish persistent backdoors.
Organizations using on-premises Exchange must immediately apply official Microsoft security updates to block these attacks. In addition to patching, security teams recommend reviewing network logs for signs of compromise, restricting external access to Exchange servers, and implementing enhanced monitoring to detect any post-exploitation activity.