
CVE-2026-42897: Microsoft Exchange — Persistent Mailbox Compromise (July 2026)
CVE-2026-42897 — Microsoft Exchange
CVE-2026-42897 is a critical cross-site scripting vulnerability in Microsoft Exchange, actively exploited by the Russia-affiliated Laundry Bear (TA488) group. The flaw allows remote attackers to deploy persistent backdoors, bypassing endpoint remediation and enabling full mailbox access and data exfiltration. No official CVSS score is published, but exploitation is confirmed in the wild against US and European targets.
Attack Vector
Attackers weaponize CVE-2026-42897 by sending malicious emails that exploit the XSS flaw when opened in Outlook Web Access (OWA). This triggers client-side code execution, installing the OWAReaper backdoor directly on Exchange servers. The malware grants attackers owner-level mailbox permissions, supports credential theft, and persists even after device re-imaging or endpoint cleaning. Reinfection is possible if the server remains unpatched. The campaign leverages spear-phishing and does not require user interaction beyond opening the email in OWA.
Who Is at Risk
All on-premises Microsoft Exchange deployments are vulnerable. Confirmed targets include US and European government agencies and private sector organizations. Hybrid and legacy Exchange environments are especially at risk if OWA is internet-facing and unpatched. Cloud-only Microsoft 365 tenants are not affected.
Patch & Mitigate
- Patch: Apply the July 2026 Microsoft Exchange security update immediately. No workaround is available.
- Workaround: None documented; disabling OWA is a temporary mitigation but impacts business operations.
- Detect: Review Exchange server logs for anomalous OWA activity, unexpected mailbox permission changes, and the presence of OWAReaper-related artifacts. Monitor for suspicious outbound connections from Exchange servers.
MITRE ATT&CK
- TA0001 — Initial Access: Spear-phishing emails exploit OWA to gain access.
- TA0002 — Execution: Malicious scripts execute client-side in OWA upon email open.
- TA0006 — Credential Access: OWAReaper facilitates credential theft and mailbox takeover.
Source: https://www.helpnetsecurity.com/2026/07/30/cve-2026-42897-microsoft-exchange-email-attack/
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

