Exploited in the wild Microsoft Outlook Web Access Laundry Bear nation-state Zimbra Microsoft
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
CVE Tools coverage
Russian threat actors, identified as Laundry Bear, have been exploiting a patched vulnerability in Microsoft Outlook Web Access (OWA) to maintain unauthorized access to email accounts even after credentials are rotated. The flaw, CVE-2026-42897, is being used to target U.S. and European government agencies and various industries including telecommunications, finance, and aerospace. This attack method allows attackers to deploy a sophisticated JavaScript implant called OWAReaper, which persists across device reboots and credential changes.