Max-severity Exchange server flaw under active exploitation by Kremlin hackers

by | Aug 29, 2026 | Technology

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Russian state-sponsored hackers attributed to TA488, also known as Laundry Bear and Void Blizzard, are actively exploiting a critical vulnerability in Microsoft Exchange Server to compromise unpatched systems and extract sensitive data, according to security researchers at Proofpoint.

The maximum-severity flaw, designated CVE-2026-42897, is a cross-site-scripting vulnerability that Microsoft initially provided mitigation guidance for in May and released a patch for in July. The vulnerability stems from improper filtering of HTML embedded in emails, enabling the execution of malicious JavaScript code. When a user simply opens a malicious email sent to an Outlook Web Access account, the exploit activates without requiring any additional user interaction.

Proofpoint researchers identified a previously unknown JavaScript-based backdoor called OWAReaper that the attackers deploy through this vulnerability. The malware operates entirely within the Outlook Web Access reading pane and has been described as the most sophisticated backdoor the company has observed delivered through such low-interaction attack methods. Upon execution, OWAReaper modifies the original email on the Exchange server to remove evidence of the exploit while simultaneously disabling certain OWA interface features. The malware then extracts user credentials, OAuth tokens, and other sensitive information by leveraging legitimate Outlook APIs and browser autofill functionality.

A particularly concerning aspect of the attack is the persistence mechanism. OWAReaper stores encrypted copies of itself in the browser’s local storage under legitimate OWA configuration keys, allowing it to automatically reactivate each time the user opens an Outlook Web Access session. Proofpoint emphasized that this server-side persistence remains intact even after users rotate their credentials or completely re-image their devices, requiring manual removal directly from the Exchange server infrastructure.

Proofpoint has advised affected organizations to revoke OAuth tokens, remove unauthorized folder permissions, clear specific local storage entries, and monitor for connections to identified command-and-control servers. The ongoing exploitation campaign demonstrates an evolution in the group’s attack capabilities and sophistication.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI