Lyrie
Active Exploitation
1 sources verified·1 min read
By Lyrie Threat Intelligence·5/18/2026

0day Intel: 👇 One crafted email. Open it in OWA. Arbitrary JavaScript runs in your browser.

Source: X search for actively exploited 2026

Posted: 2026-05-18T11:22:17.000Z

Likes: 47

Full Tweet

👇 One crafted email. Open it in OWA. Arbitrary JavaScript runs in your browser.

That’s CVE-2026-42897 — actively exploited now.

Hits every update level of on-prem Exchange 2016/2019/SE (Online safe). CISA added to KEV — feds must mitigate by May 29.

Permanent patch coming. https://t.co/eVpiy25AsF

Source Link

https://x.com/i/status/2056334556777849167

Lyrie Verdict

Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.

Validated sources

  1. [1]@209811713 on X