Microsoft disclosed CVE-2026-42897, a cross-site scripting flaw in on-premises Exchange Server Outlook Web Access (OWA), affecting Exchange Server 2016, 2019, and Subscription Edition. The bug can be triggered by a specially crafted email and may execute arbitrary JavaScript when a user opens the message in OWA under certain interaction conditions. Microsoft said Exchange Online is not affected and pushed an automatic mitigation through the Exchange Emergency Mitigation Service as mitigation ID M2.1.x, while also providing a scripted workaround for disconnected environments through the Exchange on-premises Mitigation Tool.
Proofpoint reported that Russia-aligned TA488 exploited the flaw in a 22 July campaign targeting U.S. and European government organizations as well as telecommunications, financial, hospitality, and aerospace entities. The operation used "half-click" emails to deliver OWAReaper, a previously unknown JavaScript implant that runs entirely inside the OWA browser context, steals credentials and tokens, and maintains persistence across browser restarts, credential changes, and even device reimaging; it also used GitHub commit messages and attacker-controlled emails for command-and-control, with data exfiltration over HTTPS and fallback DNS tunneling. Proofpoint assessed that infrastructure timing suggests the actor may have used CVE-2026-42897 as a zero-day before Microsoft's out-of-band fix.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
Proofpoint reported that the TA488 campaign delivered a previously unknown browser-resident JavaScript implant named OWAReaper. The malware operates inside the OWA browser context, steals credentials and tokens, establishes persistence in OWA and Exchange, and supports command-and-control via GitHub commit messages and attacker emails.
On July 22, 2026, Proofpoint said Russia-aligned threat actor TA488 began a campaign exploiting CVE-2026-42897 via 'half-click' emails that execute when opened in OWA. The activity targeted U.S. and European government entities as well as telecommunications, financial, hospitality, and aerospace organizations.
According to the new reference, Microsoft released a full fix for CVE-2026-42897 in June 2026 after initially warning of exploitation and providing temporary mitigations in May. This represents the patch release stage of the vulnerability response.
Microsoft published an automatic mitigation for CVE-2026-42897 through the Exchange Emergency Mitigation Service as mitigation ID M2.1.x and advised customers to enable the service if disabled. For disconnected or air-gapped environments, Microsoft also provided a scripted mitigation path using the Exchange on-premises Mitigation Tool.
On May 14, 2026, Microsoft disclosed CVE-2026-42897, a vulnerability affecting Outlook Web Access on on-premises Exchange Server 2016, 2019, and Subscription Edition. The flaw could be triggered by a specially crafted email and lead to arbitrary JavaScript execution in the browser context when opened in OWA under certain interaction conditions.
Proofpoint said the Russia-aligned actor tracked as TA488, also known as Laundry Bear/Void Blizzard, had prepared infrastructure for its Exchange OWA exploitation campaign in March 2026. The same reporting said the group exploited CVE-2026-42897 as a zero-day before Microsoft's May 14 advisory.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
12 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcehelpnetsecurity.com
Open sourcecommunity.gurucul.com
Open sourcetheregister.com
Open sourcetherecord.media
Open sourceproofpoint.com
Open sourcecert.pa
Open sourcetechcommunity.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.