Max-severity Exchange server flaw under active exploitation by Kremlin hackers

by | Aug 26, 2026 | Technology

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Russian state-sponsored hackers tracked as TA488 are actively exploiting a critical vulnerability in Microsoft Exchange Server to compromise unpatched systems and extract sensitive information, according to security researchers at Proofpoint. The group, also known as Laundry Bear and Void Blizzard, has been using the flaw to deliver sophisticated malware capable of maintaining persistent access to compromised machines.

The vulnerability, designated CVE-2026-42897, is a cross-site-scripting flaw that Microsoft initially provided mitigation guidance for in May before releasing a patch in July. The security defect stems from inadequate filtering of HTML content within emails, enabling the execution of malicious JavaScript code. Microsoft classified the vulnerability as maximum severity. TA488 may have exploited this flaw before it was publicly disclosed.

The malicious code installs a custom-built backdoor called OWAReaper, which Proofpoint describes as the most sophisticated implant ever delivered through such an attack vector. The malware operates entirely within the Outlook Web Access reading pane and performs multiple functions designed to maintain long-term access. After execution, it modifies the original email on the Exchange server to remove evidence of the exploit, disables certain interface features, and begins harvesting the victim’s credentials by monitoring autofill functionality.

The backdoor stores an encrypted copy of itself in the browser’s local storage using a legitimate Outlook configuration key, enabling automatic reactivation whenever the user accesses OWA. In many cases, the malware can obtain OAuth tokens to gain access to other authenticated user mailboxes on the same network. Significantly, this persistent access exists on the server side and remains in place even if users rotate their credentials or reinstall their systems.

Proofpoint has issued recommendations for affected organizations, including revoking and reviewing Exchange Web Services tokens, adjusting folder permissions, clearing specific browser storage elements, and monitoring for connections to identified command-and-control servers. Questions remain regarding whether the July patch or Microsoft’s emergency mitigation service eliminates existing infections.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI