Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Reported exploitedOutlook Web Access (OWA)TA488Our summary
Russian state-backed hackers are actively exploiting a high-severity vulnerability in Microsoft's Exchange Server, CVE-2026-42897, to deploy a new browser-based backdoor called OWAReaper. The flaw, a cross-site scripting (XSS) issue, allows attackers to execute malicious JavaScript simply by having users open an email in Outlook Web Access (OWA). Security firm Proofpoint reported that the group, known as TA488 and linked to the Kremlin, uses this method to gain persistent access to unpatched systems and steal sensitive data. Microsoft rated the vulnerability as maximum severity and issued a patch in July.
Ars Technica (Security) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.