Max-severity Exchange server flaw under active exploitation by Kremlin hackers

by | Aug 22, 2026 | Technology

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Kremlin-affiliated hackers tracked as TA488 are actively exploiting a critical vulnerability in Microsoft Exchange Server to compromise unpatched systems and extract sensitive data, security researchers reported Thursday. The group, also known as Laundry Bear and Void Blizzard, has previously been linked to similar campaigns targeting Zimbra email services, according to joint warnings from Proofpoint and the National Security Agency issued earlier.

The vulnerability, cataloged as CVE-2026-42897, is a cross-site-scripting flaw in Exchange Server that allows malicious JavaScript execution through improperly filtered HTML content in emails. Microsoft provided mitigation guidance in May and released a patch in July, assigning it a maximum severity rating. The flaw enables compromise through a “half-click” mechanism, meaning users need only open a malicious email sent to an Outlook Web Access account to trigger infection.

Once activated, the exploit installs a previously undocumented browser-based backdoor called OWAReaper, which Proofpoint characterizes as the most sophisticated half-click malware the company has encountered. The malware operates within the OWA reading pane, harvesting user credentials by intercepting browser autofill data and leveraging legitimate Outlook APIs to hide its presence. It stores itself in encrypted form within the browser’s local storage using standard OWA configuration keys, ensuring automatic execution whenever users access their email.

The backdoor’s persistence represents a significant threat, as it establishes server-side access that persists even after credential changes and complete device re-imaging. In many cases, the malware can capture OAuth tokens to gain broader access to mailboxes across authenticated networks. Proofpoint has advised affected organizations to revoke Exchange Web Services tokens, clear specific local storage keys, adjust folder permissions, and monitor for connections to identified command-and-control infrastructure. Uncertainty remains regarding whether existing Microsoft patches and mitigation tools fully eradicate compromised systems.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI