
CVE-2026-42897: Microsoft Exchange OWA — Stealth Backdoor via Zero-Day (July 2026)
CVE-2026-42897 — Microsoft Exchange Outlook Web Access
CVE-2026-42897 is a critical, actively exploited zero-day vulnerability in Microsoft Exchange Server’s Outlook Web Access (OWA) component. The flaw allows remote attackers to deploy persistent browser-based backdoors (notably OWAReaper) that survive credential resets and device reimaging. The vulnerability is being leveraged by Kremlin-linked TA488, with a CVSS score expected to be 9.8 or higher.
Attack Vector
Attackers exploit OWA’s web interface to inject a malicious backdoor directly into the Exchange server, using infrastructure linked to domains such as asecdns.com, acocdn.com, dnsrecursive.eu, and tdndns.com. The OWAReaper malware enables credential and OAuth token theft, mailbox access, and long-term persistence. No user interaction is required beyond exposing OWA to the internet. Traditional endpoint remediation, including password changes and device wipes, does not remove the threat.
Who Is at Risk
All organizations running unpatched Microsoft Exchange Servers with Outlook Web Access exposed to the internet are at immediate risk. This includes on-premises deployments regardless of organization size or sector. No specific organizations are confirmed affected, but targeting is global and opportunistic.
Patch & Mitigate
- Patch: Apply the official Microsoft security update for CVE-2026-42897 as soon as released. Delay increases risk of compromise.
- Workaround: If patching is not possible, restrict OWA access to trusted IPs or disable external OWA access until remediation.
- Detect: Monitor for outbound connections to asecdns.com, acocdn.com, dnsrecursive.eu, and tdndns.com. Review Exchange and IIS logs for anomalous authentication or script injection activity.
MITRE ATT&CK
- T1190 — Exploit Public-Facing Application: Attackers leverage the OWA zero-day to gain initial access.
- T1505.003 — Server Software Component: OWAReaper persists via malicious server-side components.
- T1556 — Modify Authentication Process: The malware steals credentials and OAuth tokens, bypassing standard authentication controls.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

