CVE Tools

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Ars Technica (Security)By Dan Goodin

Reported exploitedOutlook Web Access (OWA)TA488

Our summary

Russian state-backed hackers are actively exploiting a high-severity vulnerability in Microsoft's Exchange Server, CVE-2026-42897, to deploy a new browser-based backdoor called OWAReaper. The flaw, a cross-site scripting (XSS) issue, allows attackers to execute malicious JavaScript simply by having users open an email in Outlook Web Access (OWA). Security firm Proofpoint reported that the group, known as TA488 and linked to the Kremlin, uses this method to gain persistent access to unpatched systems and steal sensitive data. Microsoft rated the vulnerability as maximum severity and issued a patch in July.

Read at Ars Technica (Security)

Ars Technica (Security) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store