CVE Tools

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

BleepingComputerBy Ionut Ilascu

Reported exploitedMicrosoft Exchange Outlook Web Access (OWA)Laundry Bear

Our summary

A Russian state-backed hacking group, known as Laundry Bear or Void Blizzard, is exploiting a zero-day vulnerability in Microsoft Exchange Outlook Web Access (OWA) to gain long-term access to email accounts. The flaw, tracked as CVE-2026-42897, allows attackers to execute arbitrary JavaScript when users open specially crafted emails. This leads to the deployment of a sophisticated backdoor named OWAReaper, which enables persistent access and data theft. Security firm Proofpoint has observed this activity targeting multiple sectors, including government agencies and critical infrastructure. The exploit bypasses traditional detection methods by leveraging improper HTML sanitization and maintaining access even after system reinstallation.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store