Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Exchange Online mailbox access disruption

Service Disruption
First reported
Last updated
Happening score
H score 13
1 unique sources, 2 articles

Summary

Hide ▲

The Exchange Online service is undergoing an ongoing mailbox access disruption that can stop some users from opening cloud mailboxes through Outlook mobile and the new Outlook for Mac desktop client. Microsoft identified the cause as a newly introduced virtual account change and is reverting/disabling the change across affected environments. The issue has been present since Thursday and was still being investigated on Saturday. Microsoft has not disclosed affected regions or user counts, so the current scope remains unclear.

Related Happenings

Microsoft Teams on macOS repeated location-prompt service disruption

Service Disruption
First: 19.05.2026 19:10 Last: 19.05.2026 19:10 Sources 1

About this happening: Microsoft confirmed a **Microsoft Teams on macOS** service disruption that causes **non-dismissible location prompts** for some users, interrupting normal app use for those who en...

Microsoft Windows 11 KB5089549 cumulative update

Security Patch Release
First: 18.05.2026 11:33 Last: 18.05.2026 11:33 Sources 1

About this happening: Microsoft's **KB5089549** **Windows 11** security update is failing to install on some systems, forcing affected devices to roll back during reboot. The problem is tied to a nearl...

Microsoft Exchange CVE-2026-42897 mitigation advisory

Advisory/Mitigation
First: 15.05.2026 12:40 Last: 15.05.2026 12:40 Sources 1

About this happening: **Microsoft** issued immediate mitigation guidance for **CVE-2026-42897**, reducing risk for **Exchange Server 2016, 2019, and Subscription Edition (SE)** on-premises servers that...

Latest development: 15.05.2026 15:35

Microsoft issued temporary mitigation guidance for CVE-2026-42897 while a patch is still in development, recommending the Exchange Emergency Mitigation (EM) Service, which is enabled by default and can be checked with the Exchange Health Checker script, or the Exchange On-premises Mitigation Tool (EOMT) for disconnected or air-gapped environments. Microsoft noted that the mitigations can disrupt features such as OWA Print Calendar and Inline images, and that servers older than March 2023 cannot receive new mitigations through EM Service.

Microsoft Exchange Server spoofing/XSS flaw under active exploitation (CVE-2026-42897)

Vulnerability
First: 15.05.2026 09:19 Last: 15.05.2026 09:19 Sources 1

About this happening: **CVE-2026-42897** is an **actively exploited** **spoofing/XSS** flaw in **on-premises Microsoft Exchange Server** that can let attackers trigger **arbitrary JavaScript** in a bro...

Microsoft Windows Autopatch fix for EU restricted driver update deployment bug

Security Tool/Service
First: 13.05.2026 17:36 Last: 13.05.2026 17:36 Sources 1

About this happening: **Microsoft** fixed a **Windows Autopatch** service bug that let **restricted driver updates** reach some managed devices in the **EU**, bypassing admin approval controls and crea...

Timeline

  1. 23.03.2026 14:17 1 articles · 2mo ago

    Exchange Online mailbox access disruption begins

    Initial Disclosure

    Microsoft Exchange Online users began experiencing intermittent mailbox access failures through Outlook mobile apps and the new Outlook for Mac desktop client starting Thursday, and Microsoft later tracked the service issue as EX1256020.

    Show sources
  2. 23.03.2026 14:17 2 articles · 2mo ago

    Microsoft reverts the Exchange Online virtual account change

    Mitigation Patch Update

    After identifying a newly introduced virtual account change as the root cause of the Exchange Online access problem and failing to resolve it by restarting affected infrastructure, Microsoft began reverting and disabling the change across affected environments on Saturday.

    Show sources