Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
And we all thought the AI agent swarm attack was just a one-off…
SU Group Secures Exclusive Distribution Rights for Portable X-Ray Syst...
SU Group Holdings Limited Announces Proposed Acquisition of KM Safety ...
AI an existential risk – and what to do about it today
ASOCIO Digital & AI Summit 2026
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      The recovery-first approach to data resilience

      The recovery-first approach to data resilience

      Monday, September 7, 2026, 4:21 PM Asia/Singapore | Features
    • Featured

      Dealing with agentic AI governance and resilience challenges

      Dealing with agentic AI governance and resilience challenges

      Tuesday, September 1, 2026, 11:51 AM Asia/Singapore | Features
    • Featured

      How well do you know your agent?

      How well do you know your agent?

      Thursday, August 20, 2026, 3:21 PM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

News

Zero day vulnerability in Exchange Server enables browser-based JavaScript attacks

By CybersecAsia editors | Monday, May 18, 2026, 10:59 AM Asia/Singapore

Zero day vulnerability in Exchange Server enables browser-based JavaScript attacks

Flaw affects Outlook on the Web via cross-site scripting, prompts administrators to deploy mitigations, verify protections, especially across older on-premises environments.

On 14 May 2026, Microsoft disclosed an actively exploited zero day vulnerability (CVE02026-42897)  in on-premises Exchange Server that affects Outlook on the Web, that can let an attacker run malicious JavaScript in a victim’s browser under certain conditions.

The issue (CVSS 8.1) is being tracked as a high-severity cross-site scripting flaw, although Exchange Online is not affected. The firm is urging administrators to use its Exchange Emergency Mitigation Service, which can push temporary protections automatically to supported servers.

For organizations that cannot connect their servers to Microsoft’s service, a manual mitigation is available through Microsoft’s on-premises mitigation tool.

The warning lands at a tense moment for Exchange users, because Microsoft has repeatedly warned that older on-premises deployments are especially exposed to targeted attacks. Security experts and Microsoft have long viewed Exchange as a high-value target, and the platform has been hit before by major campaigns, including the 2021 ProxyLogon wave.

Administrators are advised to confirm that the mitigation is in place, rather than assuming it succeeded. The supplied Health Checker script is the fastest way to verify whether the temporary protection has been applied.

For organizations running older, disconnected, or heavily customized environments, the problem is especially difficult to mitigate, as some older Exchange builds cannot receive the newest mitigations automatically, which means administrators may have to act manually while waiting for a full patch. A permanent fix is still being prepared, but the timing and availability depend on the Exchange version and support status. That leaves many on-premises customers in a narrow window where temporary defenses are the only immediate protection.

In practical terms, administrators should treat the issue as urgent and check whether their servers are protected now. For organizations that still rely on on-premises Exchange, the latest disclosure is another reminder that the platform remains a frequent and attractive target for attackers.

Share:

PreviousCohesity Expands Strategic Alliance with HPE to Deliver Industry-Leading Cyber Resilience, Data Protection, and Hybrid Cloud Solutions
NextHow a Vietnamese D2C retailer built its own secure digital infrastructure

Related Posts

AI‑agent social network exposes millions of credentials and emails

AI‑agent social network exposes millions of credentials and emails

Wednesday, February 4, 2026

Cartoon avatars are fun, but can avatar apps leak your data?

Cartoon avatars are fun, but can avatar apps leak your data?

Friday, July 2, 2021

Cloud-native apps: fast to deploy, fast to be exploited by malware

Cloud-native apps: fast to deploy, fast to be exploited by malware

Tuesday, May 21, 2024

Increased digitalization necessitates greater compliance costs in APAC

Increased digitalization necessitates greater compliance costs in APAC

Thursday, March 7, 2024

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • SU Group Secures Exclusive Distribution Rights for Portable X-Ray System in Hong Kong and Macau

    Tuesday, September 15, 2026
    Second International Distribution Deal of …Read More »
  • SU Group Holdings Limited Announces Proposed Acquisition of KM Safety Solution Company Limited

    Tuesday, September 15, 2026
    HONG KONG, Sept. 15, 2026 …Read More »
  • Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA and Fujitsu MONAKA Server for sovereign AI infrastructure

    Monday, September 14, 2026
    Achieving world-class AI inference performance …Read More »
  • Aitech Introduces New C165 Rugged Single Board Computer to Help Defense Programs Build and Modernize Fielded VME Systems

    Monday, September 14, 2026
    New 6U VME SBC Delivers …Read More »
  • CyberDSA 2026 Draws Global Cyber Leaders for High-Level Talks on AI, Digital Trust and Critical Infrastructure

    Friday, September 11, 2026
    Minister of Digital Malaysia YB …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.