Microsoft Shipped Exchange CVE-2026-42897 Without a Patch. The DDQ Should Ask Whether Your Mailbox Tier's Emergency Mitigation Service Is Still Running.
technical
8 min read

Microsoft Shipped Exchange CVE-2026-42897 Without a Patch. The DDQ Should Ask Whether Your Mailbox Tier's Emergency Mitigation Service Is Still Running.

Microsoft's advisory for CVE-2026-42897 ships no security update and depends on the Exchange Emergency Mitigation Service applying M2.1.x. EMS is on by default but Microsoft itself recommends re-enabling it for administrators who turned it off. DDQs do not ask.

Harper Foley

Harper Foley

General Manager at Tribe AI. Former Navy EOD.

Share