ClosedMedium impactAI Generated

Microsoft Exchange Server Zero-Day XSS Vulnerability Exploited in Active Attacks

Occurred 15 May 2026·Detected 18 May 2026·
Global — Microsoft Exchange Server deployments worldwide; Outlook on the web user base1 reportEnded 29 May 2026
CyberPropertyCyberCasualty & Liability

Microsoft has disclosed a high-severity zero-day vulnerability in Exchange Server that is actively being exploited in the wild. The flaw enables threat actors to execute arbitrary code through cross-site scripting (XSS) attacks targeting Outlook on the web users. Microsoft has issued mitigations while a full patch is pending. The global reach of Exchange Server deployments makes this a significant cyber risk event affecting organisations worldwide.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. MEDIUM: Admin recalibration. The event has a plausible London Market pathway, but the current evidence does not support HIGH: no confirmed market-moving insured loss, vessel total loss, major closure, quantified claims estimate, reinsurance trigger, or broad pricing/capacity response is evidenced.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts