All incidents

TA488 exploits CVE-2026-42897 to deploy OWAReaper in Outlook

vulnerabilityopenJun 11, 2026 — Jul 29, 2026
TA488 exploits CVE-2026-42897 to deploy OWAReaper in Outlook

TA488, a Russia-aligned cyber-espionage group, has been observed exploiting CVE-2026-42897 to plant a browser implant dubbed OWAReaper inside Microsoft Outlook Web Access, hitting government, telecom, finance, hospitality and aerospace targets across the United States and Europe. The activity was first highlighted in Proofpoint research published in June 2026.

The flaw, tracked as CVE-2026-42897 and scored CVSS 8.1, is a spoofing and cross‑site scripting vulnerability that lets attackers run arbitrary JavaScript when a victim opens a specially crafted email, requiring no further interaction. It impacts Exchange Server Subscription Edition as well as the 2016 and 2019 on‑premises releases, and details are available in the Microsoft security update guide.

Once installed, OWAReaper embeds itself within Outlook Web Access settings, allowing it to survive mailbox reloads and harvest credentials, session tokens and other sensitive data. The implant communicates with its operators over an encrypted channel and can execute arbitrary commands inside the victim’s browser session. This behaviour was detailed in SecurityOnline’s analysis of the campaign.

CISA placed CVE-2026-42897 on its Known Exploited Vulnerabilities catalog, obliging federal agencies to apply fixes by the mandated deadline, and TA488 began leveraging the flaw in earnest on 22 July 2026. The group’s targeting spans multiple critical sectors, reflecting a shift toward opportunistic, wide‑net espionage rather than narrowly focused intrusions.

Defenders should apply the June 2026 Patch Tuesday updates for Exchange Server without delay, as Microsoft marked the fix as critical. Beyond patching, administrators are urged to audit OWA configurations for unexpected JavaScript injections, review mailbox rules for anomalous forwarding, and enforce multi‑factor authentication on all Outlook Web Access logins.

Organisations should also consider disabling legacy authentication protocols that could bypass MFA, block automatic loading of external content in emails, and leverage Exchange Online Protection or Microsoft Defender for Office 365 to detect malicious scripts. Continuous monitoring of OWA login logs for unusual geographic or IP patterns can help catch any implant that slipped through before patching.

Intelligence briefing updated Jul 29, 2026

CVE-2026-42897 8.1 KEV TA488
Root sourcewww.proofpoint.com
Timeline Coverage

Swipe to explore timeline