Microsoft Patches Exploited Exchange Server Vulnerability

2026-06-11T07:24:06Z4d8a5baefcb4685180494654fdb2edaa598caffe8fee8a213930f3c97b3911e5
CVE-2026-42897ClarotyExchange ServerFortinetHVACIvantiMicrosoftMicrosoft DefenderOS command injectionRoguePlanetServiceNowTrane Tracer SC+UPSVertivWindowscredential theftdata center disruptioninfostealerslocal privilege escalationpatchremote code executionzero-day

What happened

SecurityWeek roundup: Microsoft released patches for an actively exploited Exchange Server zero-day (CVE-2026-42897) disclosed May 14. ServiceNow updated hosted instances to remediate a vulnerability reportedly exploited in the wild. Fortinet and Ivanti fixed critical, unauthenticated OS command injection flaws that can lead to remote arbitrary code execution. Claroty disclosed critical HVAC and UPS security issues impacting Vertiv UPS network cards and the Trane Tracer SC+ controller that could disrupt data-center operations. A new Windows exploit named “RoguePlanet” was released that abusesa

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
4d8a5baefcb4685180494654fdb2edaa598caffe8fee8a213930f3c97b3911e5
Enrichment time
2026-06-11T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.