Microsoft confirms two actively exploited zero-day vulnerabilities in Exchange Server
Microsoft has issued a security notice about two zero-day vulnerabilities with its own Microsoft Exchange Server. Versions 2013, 2016 and 2019 of the software are affected.
Microsoft Security Response Center Microsoft Exchange Online Microsoft Exchange Server Microsoft Exchange Side Request Forgery Remote Powershell
Source: betanews.com