CVE Tools
Back to feed
Exploited in the wild Outlook Web Access (OWA) TA488 zero-day Microsoft Laundry Bear

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Ars Technica (Security)·By Dan Goodin··1 min read
CVE Tools coverage

Russian state-backed hackers are actively exploiting a high-severity vulnerability in Microsoft's Exchange Server, CVE-2026-42897, to deploy a new browser-based backdoor called OWAReaper. The flaw, a cross-site scripting (XSS) issue, allows attackers to execute malicious JavaScript simply by having users open an email in Outlook Web Access (OWA). Security firm Proofpoint reported that the group, known as TA488 and linked to the Kremlin, uses this method to gain persistent access to unpatched systems and steal sensitive data. Microsoft rated the vulnerability as maximum severity and issued a patch in July.