Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Securing the agentic enterprise – at machine speed
AI drives surge in software vulnerability disclosures in 2026: analysi...
CyberLogitec Brings Tag-Free Collision Prevention to Busan New Port
Operation KillSwitch seizes threat group infrastructure after investig...
Aligning with Global Regulations: iMQ Technology’s SQ713x Secure...
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      Securing the agentic enterprise – at machine speed

      Securing the agentic enterprise – at machine speed

      Tuesday, October 6, 2026, 5:00 PM Asia/Singapore | Features, Newsletter
    • Featured

      Why Businesses Need to Treat AI Agents Like Privileged Insiders

      Why Businesses Need to Treat AI Agents Like Privileged Insiders

      Thursday, October 1, 2026, 10:00 AM Asia/Singapore | Expert Opinion, Features, Sponsored
    • Featured

      Shadow AI Is the New Insider Threat

      Shadow AI Is the New Insider Threat

      Monday, September 21, 2026, 9:11 AM Asia/Singapore | Features, Newsletter, Sponsored, Tips
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

News

Zero day vulnerability in Exchange Server enables browser-based JavaScript attacks

By CybersecAsia editors | Monday, May 18, 2026, 10:59 AM Asia/Singapore

Zero day vulnerability in Exchange Server enables browser-based JavaScript attacks

Flaw affects Outlook on the Web via cross-site scripting, prompts administrators to deploy mitigations, verify protections, especially across older on-premises environments.

On 14 May 2026, Microsoft disclosed an actively exploited zero day vulnerability (CVE02026-42897)  in on-premises Exchange Server that affects Outlook on the Web, that can let an attacker run malicious JavaScript in a victim’s browser under certain conditions.

The issue (CVSS 8.1) is being tracked as a high-severity cross-site scripting flaw, although Exchange Online is not affected. The firm is urging administrators to use its Exchange Emergency Mitigation Service, which can push temporary protections automatically to supported servers.

For organizations that cannot connect their servers to Microsoft’s service, a manual mitigation is available through Microsoft’s on-premises mitigation tool.

The warning lands at a tense moment for Exchange users, because Microsoft has repeatedly warned that older on-premises deployments are especially exposed to targeted attacks. Security experts and Microsoft have long viewed Exchange as a high-value target, and the platform has been hit before by major campaigns, including the 2021 ProxyLogon wave.

Administrators are advised to confirm that the mitigation is in place, rather than assuming it succeeded. The supplied Health Checker script is the fastest way to verify whether the temporary protection has been applied.

For organizations running older, disconnected, or heavily customized environments, the problem is especially difficult to mitigate, as some older Exchange builds cannot receive the newest mitigations automatically, which means administrators may have to act manually while waiting for a full patch. A permanent fix is still being prepared, but the timing and availability depend on the Exchange version and support status. That leaves many on-premises customers in a narrow window where temporary defenses are the only immediate protection.

In practical terms, administrators should treat the issue as urgent and check whether their servers are protected now. For organizations that still rely on on-premises Exchange, the latest disclosure is another reminder that the platform remains a frequent and attractive target for attackers.

Share:

PreviousCohesity Expands Strategic Alliance with HPE to Deliver Industry-Leading Cyber Resilience, Data Protection, and Hybrid Cloud Solutions
NextHow a Vietnamese D2C retailer built its own secure digital infrastructure

Related Posts

Q4 2020 saw slowdown of RDP attack surge but a rise in supply-chain attacks

Q4 2020 saw slowdown of RDP attack surge but a rise in supply-chain attacks

Monday, February 15, 2021

Survey examines how people of different age groups perceive social media security

Survey examines how people of different age groups perceive social media security

Wednesday, January 15, 2025

Know your customer, but not by using search engines!

Know your customer, but not by using search engines!

Friday, August 27, 2021

Check out December 2019’s malware chart toppers

Check out December 2019’s malware chart toppers

Friday, January 17, 2020

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

LEARN MORE

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • CyberLogitec Brings Tag-Free Collision Prevention to Busan New Port

    Tuesday, October 6, 2026
    Digital twin places workers and …Read More »
  • Aligning with Global Regulations: iMQ Technology’s SQ713x Secure Element Achieves SESIP and PSA Certified Level 3

    Monday, October 5, 2026
    Passes Keysight’s physical attack testing …Read More »
  • Cymulate Receives Frost & Sullivan’s 2026 Indian Competitive Strategy Leadership Recognition for Advancing Continuous Security Validation

    Monday, October 5, 2026
    The recognition highlights Cymulate’s competitive …Read More »
  • CyberDSA 2026 Opens in Kuala Lumpur as Malaysia’s AI Ambition Puts Cybersecurity, Trust and Sovereign Capability in Sharper Focus

    Monday, October 5, 2026
    As CyberDSA opens its fourth …Read More »
  • Dahua and PARC Foundation Join Forces to Protect Dreams and Empower Young Filipino Talent

    Monday, October 5, 2026
    TAGUIG CITY, Philippines, Oct. 5, …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.