Actively exploited XSS zero-day in Exchange Server OWA (CVE-2026-42897). Microsoft released permanent patch KB5094139 on June 9, 2026. Exchange 2016/2019 require ESU Period 2. EEMS temporary mitigation, version table, SU installation procedure, exploitation detection, and Exchange Online migration recommendations.
Microsoft’s June 2026 Patch Tuesday is the largest ever: 206 CVEs + 3 active zero-days (HTTP/2 Bomb, BitLocker bypass, Windows CTF EoP). IIS HTTP.sys mitigation, DC patching order, BitLocker recovery key security, and VS Code GitHub token rotation. Step-by-step priority list and procedure for sysadmins.




