Microsoft warns of an actively exploited Exchange Server zero-day flaw, CVE-2026-42897, urging administrators to use the Emergency Mitigation Service until a patch arrives.