CVE Tools
Back to feed
Exploited in the wild Microsoft Exchange Outlook Web Access (OWA) Laundry Bear web-app Microsoft malware

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

BleepingComputer·By Ionut Ilascu··4 min read
CVE Tools coverage

A Russian state-backed hacking group, known as Laundry Bear or Void Blizzard, is exploiting a zero-day vulnerability in Microsoft Exchange Outlook Web Access (OWA) to gain long-term access to email accounts. The flaw, tracked as CVE-2026-42897, allows attackers to execute arbitrary JavaScript when users open specially crafted emails. This leads to the deployment of a sophisticated backdoor named OWAReaper, which enables persistent access and data theft. Security firm Proofpoint has observed this activity targeting multiple sectors, including government agencies and critical infrastructure. The exploit bypasses traditional detection methods by leveraging improper HTML sanitization and maintaining access even after system reinstallation.