logo

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

ID: 214b4e0b-4304-5c38-a7df-865071c25bff

STIX ID: report--214b4e0b-4304-5c38-a7df-865071c25bff

Feed Name: Proofpoint Blog

Threat Score
92/100

Date Published: 2026-07-30

Date Updated: 2026-08-01

...
...

Proofpoint and the NSA reported that Russian state-aligned group TA488 exploited a maximum-severity XSS vulnerability (CVE-2026-42897) in Microsoft Exchange/OWA to deliver a novel browser-based backdoor named OWAReaper via 'half-click' email messages; the implant gives persistent access to OWA accounts and is used to steal credentials and sensitive data, and Microsoft released mitigations and a July patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.