Microsoft warns customers about a high-severity Exchange Server vulnerability that is being exploited in real-world attacks. The flaw is reported to involve cross-site scripting (XSS), which can allow threat actors to execute arbitrary code. Microsoft’s guidance focuses on affected Exchange Server versions and provides mitigations to reduce risk until a permanent fix is available.

Both outlets report that Microsoft publicly shares workaround and mitigation steps rather than an immediate full patch. The vulnerability is identified by a CVE label, and Microsoft recommends applying the provided mitigations for organizations running impacted Exchange Server builds. The activity is also described as targeting Outlook on the web users.

SecurityWeek and Bleeping Computer both emphasize that exploitation is occurring “in the wild” and that the mitigation steps are intended as an interim measure. Organizations are advised to follow Microsoft’s published instructions and continue monitoring vendor updates for the eventual permanent patch.