Ars Technica
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Thursday, July 30, 2026
Microsoft's Exchange server vulnerability is being actively exploited by Russian state-sponsored hackers, according to cybersecurity researchers. The flaw allows attackers to gain persistent access to servers even after administrators reset credentials or reimage disks. Microsoft released a patch for the vulnerability on January 9, 2026. Security researchers identified the exploitation campaign targeting organizations in the United States and Europe.
