Back to Blog
CVE-2026-42897: Microsoft Exchange OWA — Persistent Mailbox Compromise (June 2026)
vulnerabilities

CVE-2026-42897: Microsoft Exchange OWA — Persistent Mailbox Compromise (June 2026)

breachwire TeamJul 30, 20262 min read

CVE-2026-42897 — Microsoft Exchange OWA

CVE-2026-42897 is a critical zero-day vulnerability in Microsoft Exchange Outlook Web Access (OWA) currently exploited by Russian threat actor Laundry Bear (Void Blizzard, TA488). The flaw enables attackers to gain long-term unauthorized access to mailboxes, steal credentials, and maintain persistence via server-side permissions. Active exploitation is confirmed in U.S. and European government and industry organizations.

Attack Vector

Attackers leverage a half-click XSS email exploit to trigger code execution within OWA. The malicious email, when previewed or partially interacted with, executes JavaScript that delivers the OWAReaper backdoor. This malware establishes persistent access by modifying mailbox permissions and exfiltrates data through multiple command-and-control (C2) channels, including GitHub, HTTPS, and DNS. No user download or explicit click is required, increasing the risk of silent compromise.

Who Is at Risk

All organizations running on-premises or hybrid Microsoft Exchange servers with OWA enabled are vulnerable. Confirmed victims include multiple U.S. and European government and industry entities. Cloud-only Microsoft 365 deployments are not currently affected, but hybrid environments remain at risk until patched.

Patch & Mitigate

  • Patch: Apply the latest Microsoft Exchange security update addressing CVE-2026-42897 as soon as released. Monitor Microsoft advisories for patch availability.
  • Workaround: If patching is not possible, restrict OWA access to trusted networks and disable OWA for high-risk users.
  • Detect: Review Exchange and IIS logs for anomalous OWA activity, unexpected mailbox permission changes, and outbound connections to GitHub, suspicious HTTPS endpoints, or unusual DNS queries.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers gain access via malicious OWA email exploiting XSS.
  • TA0005 — Defense Evasion: OWAReaper maintains access by modifying server-side permissions and using multiple C2 channels.
  • TA0009 — Collection: Persistent mailbox access enables ongoing data exfiltration.

Source: https://www.hendryadrian.com/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: