Skip to content

// #log-analysis

1 article

🛡️ SecOps

Exchange CVE-2026-42897 Threat Hunting Guide: Identifying Session Hijacking in OWA Logs

With no patch available for the actively exploited Exchange OWA session hijacking zero-day, security teams must hunt for existing compromise rather than waiting for a fix. This guide covers the specific log sources, KQL queries, and behavioural indicators that reveal CVE-2026-42897 exploitation in on-premises Exchange and Microsoft 365 hybrid environments.

#exchange +6