Max-severity Exchange server flaw under active exploitation by Kremlin hackers
ID: 214b4e0b-4304-5c38-a7df-865071c25bff
STIX ID: report--214b4e0b-4304-5c38-a7df-865071c25bff
Feed Name: Proofpoint Blog
Threat Score
Proofpoint and the NSA reported that Russian state-aligned group TA488 exploited a maximum-severity XSS vulnerability (CVE-2026-42897) in Microsoft Exchange/OWA to deliver a novel browser-based backdoor named OWAReaper via 'half-click' email messages; the implant gives persistent access to OWA accounts and is used to steal credentials and sensitive data, and Microsoft released mitigations and a July patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
