arstechnica.com 7/30/2026, 9:30:39 PM · external

Russian hackers use Exchange XSS bug to plant OWAReaper

Russian hackers use Exchange XSS bug to plant OWAReaper
Developing story vulnerability 4 articles tracked
TA488 exploits CVE-2026-42897 to deploy OWAReaper in Outlook
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
TA488

RUSSIAN state hackers, identified as TA488, are exploiting a critical vulnerability (CVE-2026-42897) in Microsoft's Exchange Server, allowing them to gain unauthorized access to unpatched networks. This vulnerability, described as a cross-site-scripting flaw, lets attackers execute malicious JavaScript simply by having a victim open a malicious email.

TA488 has developed a new backdoor, named OWAReaper, which runs entirely within the Outlook Web Access (OWA) interface, extracting sensitive information like credentials. Microsoft's mitigation advice, released in May and patched in July, aims to address this vulnerability. Proofpoint advises affected users to take immediate action, including audit of tokens and removal of permissions, to neutralize threats.

View Primary Source Via arstechnica.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline